Welcome, Guest. Please login or register.
Did you miss your activation email?
+  pfSense Forum
|-+  pfSense English Support» Firewalling» My pfsense failed an audit by securitymetrics.com
Username:
Password:
 
 

Pages: 1 [2] 3 4   Go Down
  Print  
Author Topic: My pfsense failed an audit by securitymetrics.com  (Read 6775 times)
0 Members and 1 Guest are viewing this topic.
jlepthien
Hero Member
*****
Offline Offline

Posts: 657



View Profile
« Reply #15 on: March 04, 2010, 02:08:51 am »

Like the second one. That's what I do...
Logged

| apple fanboy | music lover | network and security specialist | in love with cisco systems |
kapara
Sr. Member
****
Offline Offline

Posts: 489


View Profile
« Reply #16 on: March 04, 2010, 02:30:15 am »

When I use the one with ssh-rsa I get connection refused.  When I go to auth in putty and select the private.pkk file and try to open the connection I get connection error.
Logged

Skype ID:  Marinhd
jlepthien
Hero Member
*****
Offline Offline

Posts: 657



View Profile
« Reply #17 on: March 04, 2010, 02:32:35 am »

Did you get your key by opening puttygen and loading your private key there?
Logged

| apple fanboy | music lover | network and security specialist | in love with cisco systems |
kapara
Sr. Member
****
Offline Offline

Posts: 489


View Profile
« Reply #18 on: March 04, 2010, 02:33:49 am »

I generate public key and copy then export private key. Right?
Logged

Skype ID:  Marinhd
jlepthien
Hero Member
*****
Offline Offline

Posts: 657



View Profile
« Reply #19 on: March 04, 2010, 02:35:45 am »

You can use puttygen to generate a pair and then copy the key from the top of the window which says "Public key for pasting into OpenSSH authorized_keys file:"...
Logged

| apple fanboy | music lover | network and security specialist | in love with cisco systems |
kapara
Sr. Member
****
Offline Offline

Posts: 489


View Profile
« Reply #20 on: March 04, 2010, 02:39:26 am »

Here is a new example:

ssh-rsa AAAAB3NzaC1yc2EAAAABJQAAAIBb5HVQf5Nbdu6+bC2dE2bM1ZNC/7USV/jJRcRNtBSu9plZCEAz4BRwCkMiuHlFNHT+FO6fjcdg9Jzb/csZ8SyVP9wY0iSDYeDd9eY5N04LceCGb2AxqrL24a09BftVSlQnXvbsPaume+fKgVVMo6NCDoUhPI917PUyIlNZ8YBD9w== rsa-key-20100303

I pasted this into System:Advanced:Secure Shell:Authorized Keys.  Saved.

Then open Putty and loaded session with internal pfsense IP.  Clicked on Auth in Putty and browsed to the Private.pkk file which I downloaded from puttygen.

Fail.  Huh
« Last Edit: March 04, 2010, 02:41:18 am by kapara » Logged

Skype ID:  Marinhd
jlepthien
Hero Member
*****
Offline Offline

Posts: 657



View Profile
« Reply #21 on: March 04, 2010, 02:42:53 am »

Yep. That sounds about right. Are you running 1.2.3 also?
Logged

| apple fanboy | music lover | network and security specialist | in love with cisco systems |
kapara
Sr. Member
****
Offline Offline

Posts: 489


View Profile
« Reply #22 on: March 04, 2010, 02:43:34 am »

1.2.3-RELEASE
built on Mon Dec 7 20:21:30 EST 2009
Logged

Skype ID:  Marinhd
kapara
Sr. Member
****
Offline Offline

Posts: 489


View Profile
« Reply #23 on: March 04, 2010, 02:44:34 am »

Should I remove:   rsa-key-20100303 from the end of the key?
Logged

Skype ID:  Marinhd
jlepthien
Hero Member
*****
Offline Offline

Posts: 657



View Profile
« Reply #24 on: March 04, 2010, 02:45:48 am »

Nope. I have that, too....

Please check when logged in that the key is really there....

cat .ssh/authorized_keys
Logged

| apple fanboy | music lover | network and security specialist | in love with cisco systems |
kapara
Sr. Member
****
Offline Offline

Posts: 489


View Profile
« Reply #25 on: March 04, 2010, 02:47:22 am »

you mean check via winscp?
Logged

Skype ID:  Marinhd
jlepthien
Hero Member
*****
Offline Offline

Posts: 657



View Profile
« Reply #26 on: March 04, 2010, 02:48:12 am »

No. Login via putty and ssh. And then do that command in /root
Logged

| apple fanboy | music lover | network and security specialist | in love with cisco systems |
kapara
Sr. Member
****
Offline Offline

Posts: 489


View Profile
« Reply #27 on: March 04, 2010, 02:53:17 am »

Seems to be going from Bad to worse.

I deleted the key and unchecked the box disabling password for SSH.  No when I connect I get:

Disconnected:  No Supported authentication methods available.
Logged

Skype ID:  Marinhd
jlepthien
Hero Member
*****
Offline Offline

Posts: 657



View Profile
« Reply #28 on: March 04, 2010, 02:54:49 am »

Use your console to connect to the box...
Logged

| apple fanboy | music lover | network and security specialist | in love with cisco systems |
kapara
Sr. Member
****
Offline Offline

Posts: 489


View Profile
« Reply #29 on: March 04, 2010, 02:56:17 am »

ok.  Disables SSH and enabled and now I am back in.


cat: .ssh/authorized_keys: No such file or directory
Logged

Skype ID:  Marinhd
Pages: 1 [2] 3 4   Go Up
  Print  
 
Jump to:  

 

Page created in 0.026 seconds with 20 queries.