Uploaded image for project: 'RHEL'
  1. RHEL
  2. RHEL-5783

Regression: OpenSSH log format changed, zillion unmatched output lines in logwatch [rhel-7.5.z]

Linking RHIVOS CVEs to...Migration: Automation ...Sync from "Extern...XMLWordPrintable

    • None
    • Moderate
    • rhel-plumbers
    • ssg_core_services
    • 3
    • False
    • False
    • Hide

      None

      Show
      None
    • None
    • None
    • None
    • None
    • If docs needed, set a value
    • None
    • 57,005

      This bug was initially created as a copy of Bug #2012815

      I am copying this bug because:
      same with logwatch-7.5.5-6.el9.noarch

                                          1. Logwatch 7.5.5 (01/22/21) ####################
                                            Processing Initiated: Fri May 5 08:49:57 2023
                                            Date Range Processed: all
                                            Detail Level of Output: 10
                                            Type of Output/Format: stdout / text
                                            Logfiles for Host: ci-vm-10-0-136-191.hosted.upshift.rdu2.redhat.com

      --------------------- SSHD Begin ------------------------

      Network Read Write Errors: 1

      SSHD Killed: 1 Time

      SSHD Started: 4 Times

      Negotiation failed:
      no matching host key type found
      10.37.128.108: 1 Time
      ssh-rsa: 1 Time
      10.43.2.5: 2 Times
      sk-ecdsa-sha2-nistp256@openssh.com: 1 Time
      sk-ssh-ed25519@openssh.com: 1 Time

      Disconnecting after too many authentication failures for user:
      root : 1 Time

      Users logging in through sshd:
      root:
      10.37.128.108 (liver3.lab.eng.brq2.redhat.com): 2 Times
      ::1 (localhost): 1 Time
      10.43.2.5: 1 Time

      *Unmatched Entries*
      dispatch_protocol_error: type 90 seq 5 [preauth] : 1 Time
      invalid public DH value: <= 1 [preauth] : 1 Time
      main: sshd: ssh-rsa algorithm is disabled : 14 Times

      ---------------------- SSHD End -------------------------

      This bug was initially created as a copy of Bug #1593588

      I am copying this bug because:
      it looks like we have the same problem in RHEL8 ...

      https://beaker-archive.host.prod.eng.bos.redhat.com/beaker-logs/2021/05/53504/5350480/9956463/125671844/taskout.log

      :: [ 16:41:52 ] :: [ LOG ] ::

                                          1. Logwatch 7.4.3 (04/27/16) ####################
                                            Processing Initiated: Fri May 7 16:41:52 2021
                                            Date Range Processed: all
                                            Detail Level of Output: 10
                                            Type of Output/Format: stdout / text
                                            Logfiles for Host: ibm-x3650m4-01-vm-04.ibm2.lab.eng.bos.redhat.com

      --------------------- SSHD Begin ------------------------

      SSHD Killed: 1 Time(s)

      SSHD Started: 6 Time(s)

      Users logging in through sshd:
      root:
      ::1 (localhost): 1 time

      *Unmatched Entries*
      error: maximum authentication attempts exceeded for root from 222.186.15.26 port 54348 ssh2 [preauth] : 1 time(s)
      dispatch_protocol_error: type 90 seq 5 [preauth] : 1 time(s)
      Connection reset by 198.98.59.151 port 52432 [preauth] : 1 time(s)
      pam_sepermit(sshd:auth): Cannot determine the user's name : 1 time(s)
      invalid public DH value: <= 1 [preauth] : 1 time(s)

      ---------------------- SSHD End -------------------------

                                                1. Logwatch End #########################
                                                  :: [ 16:41:52 ] :: [ PASS ] :: Files /dev/null and logwatch.out should differ
                                                  :: [ 16:41:52 ] :: [ FAIL ] :: File 'logwatch.out' should not contain 'Unmatched Entries'

      or when run in 1minutetip:

      :: [ 07:05:11 ] :: [ LOG ] ::

                                          1. Logwatch 7.4.3 (04/27/16) ####################
                                            Processing Initiated: Mon Oct 11 07:05:11 2021
                                            Date Range Processed: all
                                            Detail Level of Output: 10
                                            Type of Output/Format: stdout / text
                                            Logfiles for Host: ci-vm-10-0-139-60.hosted.upshift.rdu2.redhat.com

      --------------------- SSHD Begin ------------------------

      SSHD Started: 2 Time(s)

      Users logging in through sshd:
      root:
      10.37.128.108 (liver3.lab.eng.brq.redhat.com): 2 times
      ::1 (localhost): 1 time
      10.43.2.140: 1 time

      *Unmatched Entries*
      Unable to negotiate with 10.43.2.140 port 37430: no matching host key type found. Their offer: sk-ssh-ed25519@openssh.com [preauth] : 1 time(s)
      Disconnected from user root 10.37.128.108 port 60118 : 1 time(s)
      error: maximum authentication attempts exceeded for root from 222.186.15.26 port 54348 ssh2 [preauth] : 1 time(s)
      Disconnected from user root ::1 port 38784 : 1 time(s)
      dispatch_protocol_error: type 90 seq 5 [preauth] : 1 time(s)
      pam_sepermit(sshd:auth): Cannot determine the user's name : 1 time(s)
      invalid public DH value: <= 1 [preauth] : 1 time(s)
      Connection reset by 198.98.59.151 port 52432 [preauth] : 1 time(s)
      Unable to negotiate with 10.43.2.140 port 37428: no matching host key type found. Their offer: sk-ecdsa-sha2-nistp256@openssh.com [preauth] : 1 time(s)

      ---------------------- SSHD End -------------------------

                                                1. Logwatch End #########################
                                                  :: [ 07:05:11 ] :: [ PASS ] :: Files /dev/null and logwatch.out should differ
                                                  :: [ 07:05:11 ] :: [ FAIL ] :: File 'logwatch.out' should not contain 'Unmatched Entries'

      This bug has been copied from bug #1504979 and has been proposed to be backported to 7.5 z-stream (EUS).

              psimovec Pavel Šimovec
              kvolny Karel Volný
              Pavel Šimovec Pavel Šimovec
              RHEL CS Plumbers QE Bot RHEL CS Plumbers QE Bot
              Votes:
              0 Vote for this issue
              Watchers:
              5 Start watching this issue

                Created:
                Updated:
                Resolved: