Project

General

Profile

Bug #5

Links in redmine emails not correct

Added by Zach Davis about 12 years ago. Updated about 12 years ago.

Status:
Resolved
Priority name:
Normal
Category name:
Redmine
Target version:
-
Start date:
2009-09-02
Due date:
% Done:

0%

Estimated time:

Description

Should be an easy fix in the redmine conf file.

History

#1 Updated by local admin about 12 years ago

Hi Andre,
I'm unable to SSH into the commons to fix this. Here's what I get:

$ ssh
ssh_exchange_identification: Connection closed by remote host

This happens both from my machine, from which I have shelled in before, and from a machine that has not.

thanks,
Lucas

#2 Updated by local admin about 12 years ago

Redmine Admin wrote:

Hi Andre,
I'm unable to SSH into the commons to fix this. Here's what I get:

$ ssh
ssh_exchange_identification: Connection closed by remote host

This happens both from my machine, from which I have shelled in before, and from a machine that has not.

thanks,
Lucas

Let's troubleshoot it.

1. Can I log in with my regular user account (apitanga)? yes.
2. Any peculiarities when trying to login as zdavis? no.

[fedora@localhost ~]$ ssh 
's password:

3. Can root su to this account? yes.

[root@lw1 ~]# su - zdavis
[zdavis@lw1 ~]$

4. Clues in sshd logs?

I see that the last time that account was used was this afternoon, but as soon as the password was accepted sshd drops the connection:
Sep  2 12:26:01 lw1 sshd[28149]: Accepted password for zdavis from 75.148.94.141 port 62762 ssh2
Sep 2 12:26:01 lw1 sshd[28149]: pam_unix(sshd:session): session opened for user zdavis by (uid=0)
Sep 2 12:26:13 lw1 sshd[28149]: pam_unix(sshd:session): session closed for user zdavis

5. Denyhosts? yes.

2009-09-02 12:26:29,511 - denyhosts   : INFO     new denied hosts: ['75.148.94.141']
But that apparently after the unsuccessful session...
So to begin with, root user removed that IP address from /etc/hosts.deny

6. Solution: I suspect that if I added that IP to /etc/hosts.allow the problem would go away.

Lucas, do you want to try logging in with that account again, before I add the IP to hosts.allow?

#3 Updated by local admin about 12 years ago

Wait... It looks like that IP got banned again!

2009-09-02 15:50:30,694 - denyhosts   : INFO     new denied hosts: ['75.148.94.141']

I checked to see if that IP is blacklisted in the central denyhosts database...

But it seems like that's not the case...

Basically the way to get banned by denyhosts is to attempt to login unsuccessfully three consecutive times.
Do you think that there could be a running process trying to login with wrong credentials?

#4 Updated by Lucas Thurston about 12 years ago

Andre,
I don't have a running process that's trying to log in periodically. The only log in that's coming from my machine is when I attempt it manually. I probably did attempt too many logins earlier -- then I found the password. :)

Lucas

#5 Updated by local admin about 12 years ago

Hmm... it looks like denyhosts is continually banning that IP address:

2009-09-02 15:55:31,231 - denyhosts   : INFO     new denied hosts: ['75.148.94.141']

We can bypass denyhosts by adding that IP address to hosts.allow, but I still don't understand the problem.
Can other clients in your network currently login? Using other accounts? just trying...

#6 Updated by Lucas Thurston about 12 years ago

Andre,
I just closed my terminal and my SFTP client applications. I've checked around the office here and noone else is attempting to login.

Let me know if anything changes.

best,
Lucas

#7 Updated by local admin about 12 years ago

I think I got it... Have to remove the IP address not only from /etc/hosts.deny, but from a couple other places as well.

I believe that as soon as that's done, logins from that IP should be ok.

One moment please...

#8 Updated by local admin about 12 years ago

Removed bad entries.
Let's try to login from that IP again!

#9 Updated by Lucas Thurston about 12 years ago

Success! Thanks, Andre.

André Pitanga wrote:

Removed bad entries.
Let's try to login from that IP again!

#10 Updated by local admin about 12 years ago

Cool, and I learned something new :)

#11 Updated by Lucas Thurston about 12 years ago

Glad to hear it. And, if I did my part right, this email will have proper links back to the site in it.

André Pitanga wrote:

Cool, and I learned something new :)

#12 Updated by Lucas Thurston about 12 years ago

That was embarrassing. Good thing it's working now.

Lucas Thurston wrote:

Glad to hear it. And, if I did my part right, this email will have proper links back to the site in it.

André Pitanga wrote:

Cool, and I learned something new :)

#13 Updated by Matt Gold about 12 years ago

  • Status changed from New to 3

#14 Updated by Matt Gold about 12 years ago

  • Status changed from 3 to Resolved

Also available in: Atom PDF