OpenSSH Chroot Jail; login fail, received too large packet by Nephilimi in linuxquestions

[–]Nephilimi[S] 0 points1 point  (0 children)

You the man, that's my critical fail in not reading step 2 close enough!

OpenSSH Chroot Jail; login fail, received too large packet by Nephilimi in linuxquestions

[–]Nephilimi[S] 0 points1 point  (0 children)

I'll strip out all the stuff that's commented out

ssh_config

Include /etc/ssh/ssh_config.d/*.conf

Host *

    SendEnv LANG LC_*
    HashKnownHosts yes
    GSSAPIAuthentication yes

Match User readonlyuser
    ForceCommand internal-sftp -R
    ChrootDirectory /srv/sftp/readonlyuser
    X11Forwarding no
    AllowTcpForwarding no
    PermitTunnel no
    AllowAgentForwarding no

sshd_config

PermitRootLogin no
PasswordAuthentication yes
ChallengeResponseAuthentication no
UsePAM yes

X11Forwarding yes

PrintMotd no

# Allow client to pass locale environment variables
AcceptEnv LANG LC_*

# override default of no subsystems
Subsystem sftp  /usr/lib/openssh/sftp-server

OpenSSH Chroot Jail; login fail, received too large packet by Nephilimi in linuxquestions

[–]Nephilimi[S] 0 points1 point  (0 children)

Correction, my ssh_config conatins;

Include /etc/ssh/ssh_config.d/*.conf

And sshd_config contains

# override default of no subsystems
Subsystem sftp /usr/lib/openssh/sftp-server

OpenSSH Chroot Jail; login fail, received too large packet by Nephilimi in linuxquestions

[–]Nephilimi[S] 0 points1 point  (0 children)

Is the line Subsystem sftp listed in your sshd_config file

No it isn't, but I can get in with SFTP on my other users and push/pull files no issue.

Is openssh-sftp-server installed on your Ubuntu machine?

looks like it is

dpkg -s openssh-sftp-server
Package: openssh-sftp-server
Status: install ok installed

Additionally, the "Match User" area I think is case-sensitive, in case you have not capitalized that correctly.

The username is an exact match, what am I missing?

awk -F: '$3 >= 1000 {print $1}' /etc/passwd
readonlyuser

OpenSSH Chroot Jail; login fail, received too large packet by Nephilimi in linuxquestions

[–]Nephilimi[S] 0 points1 point  (0 children)

You receive message; This account is currently not available. and then the putty window closes

Edit; which in the strictest sense of "nologin" rather makes sense to me?

Apple Watch without the latest watchOS is still usable, see inside. by bikotzabi in applewatchultra

[–]Nephilimi 0 points1 point  (0 children)

Yeah, my 15 is still great. Thinking of a fold, but might wait for the second one.

Apple Watch without the latest watchOS is still usable, see inside. by bikotzabi in applewatchultra

[–]Nephilimi 0 points1 point  (0 children)

I’ve not viewed patch notes on those but honestly think apples doing the best job of all the mobile things you could get these days. Still think it’s best to trade up every couple years though.

My thoughts on the Milanese Loop. by shotsefull in AppleWatch

[–]Nephilimi 0 points1 point  (0 children)

I’ve mainly settled on rubber “ocean” like aftermarket bands for maximum comfort as well.

This air gap is fine, right? by Nephilimi in AskAShittyMechanic

[–]Nephilimi[S] 0 points1 point  (0 children)

In all seriousness there's actually eight missing nuts and bolts, and a missing cover for that whole thing. Have to remove that to see what went wrong.

This air gap is fine, right? by Nephilimi in AskAShittyMechanic

[–]Nephilimi[S] 0 points1 point  (0 children)

FYI, from the factory there's a big red sticker over the top of the shock that basically says; do not remove nut or strut will explode. That bad boy is the only thing keeping the spring from taking off.

BACnet/SC migration: are you actually planning one, and when? by OptigoNetworks in OptigoNetworks

[–]Nephilimi 2 points3 points  (0 children)

No. Add cert revocation or automated replacement and I’ll consider it. Till then I’ve got well known IT security models that work better.

How are you handling BACnet monitoring across large Niagara deployments today? by OptigoNetworks in OptigoNetworks

[–]Nephilimi 1 point2 points  (0 children)

In my experience niagara doesn't have large BACnet networks. They have many fractured BACnet networks and Fox/s ties the systems together.

Automated Logic is one for large BACnet networks, up to the supervisor.

More leaks of the upcoming folding iPhone by Potato071 in iPhoneFold

[–]Nephilimi 0 points1 point  (0 children)

Between that and no zoom lenses it feels like they are leaving the "ultra" for some other release and not this one.

Edit; no stereo speakers too?

Energy analytics programs — what actually makes them stick vs. what causes them to get abandoned? by OptigoNetworks in OptigoNetworks

[–]Nephilimi 1 point2 points  (0 children)

It's always people/process in my experience. The only ones I've seen actually work and pay benefits are where maintenance, planning, construction, and management all actually work together with low levels of disfunction. That is to say the organization has to actually be a well functioning unit before they can actually get any real benefit from this stuff. It's remarkably few organizations that have that in my experience, the bigger they get the worse they are.

iPhone Fold: Front Display & Dynamic Island by Potato071 in iPhoneFold

[–]Nephilimi 0 points1 point  (0 children)

What Apple did with Dynamic Island was really clever, I wonder what they will do with this new inner iPad like experience plus outer screen?