AIX

 View Only
Expand all | Collapse all

Unable to SSH after update SSL and SSH

  • 1.  Unable to SSH after update SSL and SSH

    Posted Thu March 02, 2023 09:36 AM

    Hi hello,

    need your help ,I have AIX 6.1 currently  unable to remote the machine via ssh after install update Openssl 1.1.1 and OpenSSH 8.1 ,

    i followed instruction from this link

    https://www.ibm.com/support/pages/downloading-and-installing-or-upgrading-openssl-and-openssh.

    but all got wrong when sshd status inoperative mode

    here's the capture

    [2023-03-02 14:30:26]  root@ist_development:/etc/ssh_backup>stopse rc -s sshd
    [2023-03-02 14:30:33]  0513-044 The sshd Subsystem was requested to stop.
    [2023-03-02 14:30:33]  root@ist_development:/etc/ssh_backup>startsrc -s sshd
    [2023-03-02 14:30:42]  0513-059 The sshd Subsystem has been started. Subsystem PID is 1208564.
    [2023-03-02 14:30:43]  root@ist_development:/etc/ssh_backup>
    [2023-03-02 14:30:45]  root@ist_development:/etc/ssh_backup>
    [2023-03-02 14:30:46]  root@ist_development:/etc/ssh_backup>
    [2023-03-02 14:30:46]  root@ist_development:/etc/ssh_backup>lssrc -g ssh
    [2023-03-02 14:30:50]  Subsystem         Group            PID          Status 
    [2023-03-02 14:30:50]   sshd                   ssh                             inoperative

    thanks in advance



    ------------------------------
    Ary Syarifudin
    ------------------------------


  • 2.  RE: Unable to SSH after update SSL and SSH

    IBM Champion
    Posted Fri March 03, 2023 04:12 AM

    Hello Ary,

    try to run sshd in the debug mode and show which errors it brings:

    /usr/sbin/sshd -Dd


    ------------------------------
    Andrey Klyachkin

    https://www.power-devops.com
    ------------------------------



  • 3.  RE: Unable to SSH after update SSL and SSH

    Posted Mon March 06, 2023 12:18 AM

    Hi Andrey, thanks for  your respon... here's history that i captured from aix console directly , it was really struggle,i can not remote via ssh into it.


    bash-4.4# /usr/sbin/sshd -Dd
    exec(): 0509-036 Cannot load program /usr/sbin/sshd because of the following errors:
            0509-130 Symbol resolution failed for sshd because:
            0509-136   Symbol __stack_chk_fail (number 230) is not exported from
                       dependent module /usr/lib/libc.a(shr.o).
            0509-136   Symbol __ssp_canary_word (number 245) is not exported from
                       dependent module /usr/lib/libc.a(shr.o).
            0509-192 Examine .loader section symbols with the
                     'dump -Tv' command.
    bash-4.4# 

    thank you

    -------

    Ary



    ------------------------------
    Ary Syarifudin
    ------------------------------



  • 4.  RE: Unable to SSH after update SSL and SSH

    IBM Champion
    Posted Mon March 06, 2023 01:35 AM

    Old version of libc library? I'm not sure if the latest SSL is compatible with ancient AIX 6.1...

    Igor



    ------------------------------
    Igor Novotny
    Principal Consultant
    MHM Computer, a.s.
    Prague 15
    00420602369375
    ------------------------------



  • 5.  RE: Unable to SSH after update SSL and SSH

    Posted Mon March 06, 2023 02:11 AM

    Hi Igor

    i followed instruction from this link

    https://www.ibm.com/support/pages/downloading-and-installing-or-upgrading-openssl-and-openssh.

    and it seems that OpenSSL 1.1.1 supported for AIX 6.1

    https://www.ibm.com/resources/mrs/assets/DirectDownload?source=aixbp&lang=en_US

    BR,



    ------------------------------
    Ary Syarifudin
    ------------------------------



  • 6.  RE: Unable to SSH after update SSL and SSH

    Posted Mon March 06, 2023 02:28 AM

    Probably you have a older AIX 6.1 TL level 
    What is the output of "oslevel -s" ?



    ------------------------------
    Ayappan P
    ------------------------------



  • 7.  RE: Unable to SSH after update SSL and SSH

    Posted Mon March 06, 2023 04:14 AM

    Hi Ayyapan,

    6100-03-00-0000



    ------------------------------
    Ary Syarifudin
    ------------------------------



  • 8.  RE: Unable to SSH after update SSL and SSH
    Best Answer

    IBM Champion
    Posted Mon March 06, 2023 04:26 AM

    It's just old TL03 without any SP...

    Go to IBM Fixcentral, download 6100-09-00-1391 and 6100-09-12-1864 packages.

    Apply the first one (TL09), then the second (SP12).

    Igor.



    ------------------------------
    Igor Novotny
    Principal Consultant
    MHM Computer, a.s.
    Prague 15
    00420602369375
    ------------------------------



  • 9.  RE: Unable to SSH after update SSL and SSH

    Posted Mon March 06, 2023 10:43 PM

    Hi Igor,

    I Couldn't find 6100-09-00-1391 and 6100-09-12-1864 packages,

    below, i found two on IBM Fixcentral look alike, is this SP you mentioned before ?

    6100-09-00-1341  

    6100-09-12-1846 



    ------------------------------
    Ary Syarifudin
    ------------------------------



  • 10.  RE: Unable to SSH after update SSL and SSH

    IBM Champion
    Posted Tue March 07, 2023 02:11 AM

    Hi Ary,

    sorry for my typo - I rewrote the numbers from my phone...

    Your ID's are right :-)

    Just take into account that both steps require system reboot as the kernel and majority of system libraries are updated.

    Regards Igor.



    ------------------------------
    Igor Novotny
    Principal Consultant
    MHM Computer, a.s.
    Prague 15
    00420602369375
    ------------------------------



  • 11.  RE: Unable to SSH after update SSL and SSH

    IBM Champion
    Posted Mon March 06, 2023 03:07 AM

    Check the libc version - the latest for AIX 6.1 is: 

    bos.rte.libc   6.1.9.400

    from TL09 SP12

    Igor.



    ------------------------------
    Igor Novotny
    Principal Consultant
    MHM Computer, a.s.
    Prague 15
    00420602369375
    ------------------------------