OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • Archive »
  • 23.1 Legacy Series »
  • [SOLVED] SSH handshake error with Apache Guacamole
« previous next »
  • Print
Pages: [1]

Author Topic: [SOLVED] SSH handshake error with Apache Guacamole  (Read 4644 times)

Dncl31

  • Newbie
  • *
  • Posts: 1
  • Karma: 0
    • View Profile
[SOLVED] SSH handshake error with Apache Guacamole
« on: July 16, 2023, 10:18:35 pm »
Hello !

SSH connection between Apache Guacamole and OpnSense fails with this message : "The remote desktop server encountered an error and has closed the connection. Please try again or contact your system administrator.".

In Guacamole, the error displayed in "/var/log/syslog" is :
Code: [Select]
Jul 16 21:47:43 guacamole guacd[1256]: SSH handshake failed.
In OpnSense, the error in "var/log/audit/audit_20230716.log" is :
Code: [Select]
2023-07-16T21:42:15+02:00 XXX.XXX sshd 91432 - [meta sequenceId="1"] Unable to negotiate with 172.16.10.8 port 58772: no matching host key type found. Their offer: ssh-rsa,ssh-dss [preauth]
I use Guacamole v1.5.2, OpenSSH/OpenSSL versions are OpenSSH_8.4p1 Debian-5+deb11u1, OpenSSL 1.1.1n  15 Mar 2022.
And I use OpnSense v23.1.11-amd64, OpenSSH/OpenSSL versions are OpenSSH_9.3p1, OpenSSL 1.1.1u  30 May 2023

Is the error due to incompatibility between those versions ?
« Last Edit: July 17, 2023, 06:19:33 pm by Dncl31 »
Logged

pcaetano

  • Newbie
  • *
  • Posts: 10
  • Karma: 1
    • View Profile
Re: SSH handshake error with Apache Guacamole
« Reply #1 on: July 17, 2023, 12:31:40 am »
Hi,

ssh-rsa is a deprecated algorythm: https://marc.info/?l=openbsd-tech&m=163028217802671&w=2

It is possible to allow connecting from hosts running older openssh by adding ssh-rsa in:
System > Settings > Administration
*Click* on Show cryptographic overrides

Host key algorithms
Public key signature algorithms


Regards
Logged

  • Print
Pages: [1]
« previous next »
  • OPNsense Forum »
  • Archive »
  • 23.1 Legacy Series »
  • [SOLVED] SSH handshake error with Apache Guacamole
 

OPNsense is an OSS project © Deciso B.V. 2015 - 2024 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2