meta data for this page
Issues
userauth_pubkey: signature algorithm ssh-rsa not in PubkeyAcceptedAlgorithms [preauth]
ssh-rsa is disabled due to security reason: release-8.2
Needs to use rsa-sha2-256 or rsa-sha2-512:
ssh-keygen -t rsa-sha2-512 -b 2048
debug1: expecting SSH2_MSG_KEX_ECDH_REPLY
SSH hangs on debug1: expecting SSH2_MSG_KEX_ECDH_REPLY when using VPN (OpenVPN, MT Ipsec, … doesn't matter).
Not catched root issue yet. Internet says it is related to packet size. So some workaround sometimes works:
- reducing MTU in interface
- limiting Kex list (reduce packet size during exchange)
- specifing cipher for connection
ip li set mtu 1400 dev wlan0
ssh -c aes256-gcm@openssh.com host
ssh -o KexAlgorithms=ecdh-sha2-nistp521 username@systemname
- ~/.ssh/config
KexAlgorithms ecdh-sha2-nistp521
Source:
X11 forwarding request failed on channel 0
- /etc/ssh/sshd_config
X11Forwarding yes X11UseLocalhost no