#599017 openssh-client: Global "User" setting in .ssh/config fails

Package:
openssh-client
Source:
openssh
Description:
secure shell (SSH) client, for secure access to remote machines
Submitter:
Bart Massey
Date:
2010-10-03 19:51:04 UTC
Severity:
normal
#599017#5
Date:
2010-10-03 19:13:49 UTC
From:
To:
To save typing, my .ssh/config started with "User = bart",
which was intended to apply globally unless overriden by the
"User" setting for a particularly connection.  Although I
may be mistaken, I think the manual implies that this is
supposed to work.

Sadly, it doesn't; with this configuration, when publickey
authentication fails, rather than fall back to password
authentication the client simply repeatedly sends some bogus
public key until the server dies.  Here's a trace:

    OpenSSH_5.5p1 Debian-5, OpenSSL 0.9.8o 01 Jun 2010
    debug1: Reading configuration data /home/bart/.ssh/config
    debug1: Applying options for test
    debug1: Reading configuration data /etc/ssh/ssh_config
    debug1: Applying options for *
    debug1: Connecting to bartfan.po8.org [192.168.1.7] port 22.
    debug1: Connection established.
    debug1: identity file /home/bart/.ssh/id-rsa-test type 1
    debug1: Checking blacklist file /usr/share/ssh/blacklist.RSA-4096
    debug1: Checking blacklist file /etc/ssh/blacklist.RSA-4096
    debug1: identity file /home/bart/.ssh/id-rsa-test-cert type -1
    debug1: Remote protocol version 2.0, remote software version OpenSSH_5.5p1 Debian-5
    debug1: match: OpenSSH_5.5p1 Debian-5 pat OpenSSH*
    debug1: Enabling compatibility mode for protocol 2.0
    debug1: Local version string SSH-2.0-OpenSSH_5.5p1 Debian-5
    debug1: SSH2_MSG_KEXINIT sent
    debug1: SSH2_MSG_KEXINIT received
    debug1: kex: server->client aes128-ctr hmac-md5 none
    debug1: kex: client->server aes128-ctr hmac-md5 none
    debug1: SSH2_MSG_KEX_DH_GEX_REQUEST(1024<1024<8192) sent
    debug1: expecting SSH2_MSG_KEX_DH_GEX_GROUP
    debug1: SSH2_MSG_KEX_DH_GEX_INIT sent
    debug1: expecting SSH2_MSG_KEX_DH_GEX_REPLY
    debug1: Host 'bartfan.po8.org' is known and matches the RSA host key.
    debug1: Found key in /home/bart/.ssh/known_hosts:59
    debug1: ssh_rsa_verify: signature correct
    debug1: SSH2_MSG_NEWKEYS sent
    debug1: expecting SSH2_MSG_NEWKEYS
    debug1: SSH2_MSG_NEWKEYS received
    debug1: Roaming not allowed by server
    debug1: SSH2_MSG_SERVICE_REQUEST sent
    debug1: SSH2_MSG_SERVICE_ACCEPT received
    debug1: Authentications that can continue: publickey,password
    debug1: Next authentication method: publickey
    debug1: Offering public key: /home/bart/.ssh/id-rsa-test
    debug1: Authentications that can continue: publickey,password
    debug1: Offering public key: bart@bartfan
    debug1: Authentications that can continue: publickey,password
    debug1: Offering public key: bart@bartfan
    debug1: Authentications that can continue: publickey,password
    debug1: Offering public key: bart@bartfan
    debug1: Authentications that can continue: publickey,password
    debug1: Offering public key: bart@bartfan
    debug1: Authentications that can continue: publickey,password
    debug1: Offering public key: bart@bartfan
    Received disconnect from 192.168.1.7: 2: Too many authentication failures for bart

Moving the "User" option to be private to each connection in
the config file seems to solve the problem.