Gatt Posted February 11, 2009 Posted February 11, 2009 Got SSH working on my fedora 10 box and can login in as root fine When I try to login as a standard user however I get this... login as: user user@server password: Last login: Wed Feb 11 07:18:45 2009 from <> -bash: /etc/profile: Permission denied -bash-3.2$ If i try to then run ssh-keygen i get -bash-3.2$ ssh-keygen You don't exist, go away! -bash-3.2$ When I am logged in as root my prompt is [root@server ~]# Is this normal?
mac_shinobi Posted February 11, 2009 Posted February 11, 2009 im no linux guru but from the message it would seem you would need to alter the permissions on the /etc/profile whether thats the cause of the issue well thats another question.
rob_f Posted February 11, 2009 Posted February 11, 2009 Heard about this occasionally on fedora, can you check the permissions of /etc - as root do: # ls -al / | grep etc You should see something like: drwxr-xr-x 73 root root 4096 2009-02-10 11:15 etc But if it's drwxr----- 73 root root 4096 2009-02-10 11:15 etc Then the perms have been screwed up
Gatt Posted February 11, 2009 Author Posted February 11, 2009 drwxr-xr-x+ 153 root root 12288 2009-02-11 04:04 etc
rob_f Posted February 11, 2009 Posted February 11, 2009 Hmm looks good, how about: ls -al /etc/profile
Gatt Posted February 11, 2009 Author Posted February 11, 2009 (edited) -rwxr-xr-x 1 root root 1138 2008-11-18 14:07 /etc/profile Also # tail /var/log/secure Feb 11 09:06:59 mhs-srv-web01 sshd[1255]: Accepted password for cwilson from 10.4.24.7 port 49968 ssh2 Feb 11 09:06:59 mhs-srv-web01 sshd[1255]: pam_unix(sshd:session): session opened for user cwilson by (uid=0) Feb 11 09:07:04 mhs-srv-web01 sshd[1255]: pam_unix(sshd:session): session closed for user cwilson Edited February 11, 2009 by Gatt
rob_f Posted February 11, 2009 Posted February 11, 2009 Are you running SELinux? Type sestatus as root.
Gatt Posted February 11, 2009 Author Posted February 11, 2009 Nope - its disabled. really frustrating!
CyberNerd Posted February 11, 2009 Posted February 11, 2009 the /etc has an extended attribute set ( the +). Long shot but check that there isn;t something explicitly denying access to /etc getfacl /etc
Gatt Posted February 11, 2009 Author Posted February 11, 2009 interesting... getfacl: Removing leading '/' from absolute path names # file: etc # owner: root # group: root user::rwx user:cwilson:rw- #effective:r-- group::r-x mask::r-x other::r-x
CyberNerd Posted February 11, 2009 Posted February 11, 2009 try setfacl -m user:cwilson:rwx (or maybe just rx to be safe) not sure how to do that recursively... 1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now