[Samba] Trouble in ssh into Windows machines in the Windows/Samba Domain

Rowland penny rpenny at samba.org
Sat Apr 10 14:54:57 UTC 2021


On 10/04/2021 15:34, Nicola Mingotti wrote:
>
> Hi Rowland. I don't know where the 'sshd_config' came from, and I find 
> quite misterious you don't have
> the same lines I have.


The sshd_config is the one that is created on Windows when you 
add/enable ssh, I could only login into Windows via ssh using a password 
without touching anything.

>
> Anyway, at the moment this is the situation:
>
> 1] Password authentication with domain user OK. but NEEDS the password 
> typed id.
> Till now I have not found a way to login without it. That is, I was 
> not able to realize
> OpenSSH Single sign on.


Agree, you can only use a password with the Windows ssh server.

>
> 2] SSH login with Public key. Does not work. Here the thing is quite 
> strange, if i put
> my public key into the computer with the ssh server I can't login anymore,


Here I am different, I have placed the key where I think it should go 
and I can still login, but only using a password.


> A guy on GitHub (@remipaeta) says with Windows AD he is able to login 
> in ssh with public key
> and he finds this problem only with Samba. Maybe you can check this
> statement I don't have a Windows AD. Or maybe you know the developer 
> who is
> able to look at this corner of the code ;)


OK, on Linux, I can ssh between machines using a password, ssh keys and 
kerberos. Against the Windows ssh server, only using a password works, 
so this is unlikely to be a samba problem, to me it sounds like there is 
a problem with the Windows ssh program. There is no doubt that numerous 
things that work on Linux ssh, do not exist on Windows ssh

>
> Next thing I am going to try is if the SingleSingOn and public key auth
> work from two Linux in the Samba Windows Domain, user in the domain. I 
> will let you know.
> I need to set up another Linux in the domain to make the experiment.


I can assure that they do work on Linux, but I cannot get them to work 
on windows.

Rowland





More information about the samba mailing list