<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Unable to SSH using public key from Ubuntu 22 VM in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unable-to-SSH-using-public-key-from-Ubuntu-22-VM/m-p/160152#M28210</link>
    <description>&lt;P&gt;I migrated from a Debian 9 to Ubuntu 22 bastion host this week, and am unable to SSH to CheckPoint R80.40 gateways using public key authentication.&amp;nbsp; &amp;nbsp;Initially I was unable to SSH to the CheckPoints at all, but was able to fix that but adding the following lines to /etc/ssh/ssh_config:&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier"&gt; KexAlgorithms +diffie-hellman-group14-sha1&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;HostKeyAlgorithms=+ssh-dss&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;This fixed the connection, and I can now authenticate via username/password.&amp;nbsp; However, public key auth is failing.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It's a bit of a concern since we have multiple R80.40 (and a few R80.30) devices in public cloud, where public ssh key auth is the only way to do initial configuration (username/password only works for GAIA web interface)&lt;/P&gt;
&lt;P&gt;Server Info:&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier"&gt;ssh -V&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;OpenSSH_7.8p1, OpenSSL 1.1.1n 15 Mar 2022&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;Client Info:&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier"&gt;lsb_release -a&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;No LSB modules are available.&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Distributor ID: Ubuntu&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Description: Ubuntu 22.04.1 LTS&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Release: 22.04&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Codename: jammy&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier"&gt;ssh -V&lt;BR /&gt;OpenSSH_8.9p1 Ubuntu-3, OpenSSL 3.0.2 15 Mar 2022&lt;/FONT&gt;&lt;/P&gt;</description>
    <pubDate>Sat, 22 Oct 2022 13:58:11 GMT</pubDate>
    <dc:creator>johnnyringo</dc:creator>
    <dc:date>2022-10-22T13:58:11Z</dc:date>
    <item>
      <title>Unable to SSH using public key from Ubuntu 22 VM</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unable-to-SSH-using-public-key-from-Ubuntu-22-VM/m-p/160152#M28210</link>
      <description>&lt;P&gt;I migrated from a Debian 9 to Ubuntu 22 bastion host this week, and am unable to SSH to CheckPoint R80.40 gateways using public key authentication.&amp;nbsp; &amp;nbsp;Initially I was unable to SSH to the CheckPoints at all, but was able to fix that but adding the following lines to /etc/ssh/ssh_config:&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier"&gt; KexAlgorithms +diffie-hellman-group14-sha1&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;HostKeyAlgorithms=+ssh-dss&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;This fixed the connection, and I can now authenticate via username/password.&amp;nbsp; However, public key auth is failing.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It's a bit of a concern since we have multiple R80.40 (and a few R80.30) devices in public cloud, where public ssh key auth is the only way to do initial configuration (username/password only works for GAIA web interface)&lt;/P&gt;
&lt;P&gt;Server Info:&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier"&gt;ssh -V&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;OpenSSH_7.8p1, OpenSSL 1.1.1n 15 Mar 2022&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;Client Info:&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier"&gt;lsb_release -a&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;No LSB modules are available.&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Distributor ID: Ubuntu&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Description: Ubuntu 22.04.1 LTS&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Release: 22.04&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Codename: jammy&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier"&gt;ssh -V&lt;BR /&gt;OpenSSH_8.9p1 Ubuntu-3, OpenSSL 3.0.2 15 Mar 2022&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 22 Oct 2022 13:58:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unable-to-SSH-using-public-key-from-Ubuntu-22-VM/m-p/160152#M28210</guid>
      <dc:creator>johnnyringo</dc:creator>
      <dc:date>2022-10-22T13:58:11Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to SSH using public key from Ubuntu 22 VM</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unable-to-SSH-using-public-key-from-Ubuntu-22-VM/m-p/160154#M28211</link>
      <description>&lt;P&gt;What does the client side ssh say if you attempt to connect with the "-vvv" option for full debug output?&lt;/P&gt;</description>
      <pubDate>Sat, 22 Oct 2022 15:30:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unable-to-SSH-using-public-key-from-Ubuntu-22-VM/m-p/160154#M28211</guid>
      <dc:creator>Swiftyyyy</dc:creator>
      <dc:date>2022-10-22T15:30:43Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to SSH using public key from Ubuntu 22 VM</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unable-to-SSH-using-public-key-from-Ubuntu-22-VM/m-p/160221#M28220</link>
      <description>&lt;P&gt;Just to make sure I understand this correctly, it is the SSH client who is providing the public key to authenticate to Gaia? There is a couple of SKs you may find useful:&amp;nbsp;&lt;SPAN&gt;sk143752 &amp;amp;&amp;nbsp;sk164234&lt;BR /&gt;&lt;BR /&gt;If anything, please let me know&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 24 Oct 2022 08:52:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unable-to-SSH-using-public-key-from-Ubuntu-22-VM/m-p/160221#M28220</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2022-10-24T08:52:14Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to SSH using public key from Ubuntu 22 VM</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unable-to-SSH-using-public-key-from-Ubuntu-22-VM/m-p/160280#M28234</link>
      <description>&lt;P&gt;Right - just to clarify, the checkpoint gateway (server) has the ssh public key, the client has the private key.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have noticed Ubuntu 22 has been fairly aggressive about dropping support for older ciphers and key lengths, so had assumed it was that.&amp;nbsp; But the funny thing is I can do public key auth to some checkpoints but not others.&amp;nbsp; All of them are running R80.40 Take 173 and seem to have the same openssh version and configuration.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 24 Oct 2022 18:34:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unable-to-SSH-using-public-key-from-Ubuntu-22-VM/m-p/160280#M28234</guid>
      <dc:creator>johnnyringo</dc:creator>
      <dc:date>2022-10-24T18:34:24Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to SSH using public key from Ubuntu 22 VM</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unable-to-SSH-using-public-key-from-Ubuntu-22-VM/m-p/160308#M28247</link>
      <description>&lt;P&gt;Did you look into the SKs I have provided to you? Also, who is refusing to connect, the GW or your client?&lt;/P&gt;</description>
      <pubDate>Tue, 25 Oct 2022 07:39:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unable-to-SSH-using-public-key-from-Ubuntu-22-VM/m-p/160308#M28247</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2022-10-25T07:39:17Z</dc:date>
    </item>
  </channel>
</rss>

