LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > CentOS
User Name
Password
CentOS This forum is for the discussion of CentOS Linux. Note: This forum does not have any official participation.

Notices


Reply
  Search this Thread
Old 05-14-2020, 12:35 PM   #1
fat256
LQ Newbie
 
Registered: May 2020
Posts: 5

Rep: Reputation: Disabled
Error sshd banner line


Hi,

Using Centos 8.1 , i have errors on log /var/log/secure like

May 14 19:25:41 XXXXXX sshd[9690]: error: kex_exchange_identification: banner line contains invalid characters

message appear each minutes ....

on /etc/ssh/sshd_config , i have Banner none with #.

an idea how i can find causes of these message ????

Thanks
 
Old 05-14-2020, 04:16 PM   #2
ondoho
LQ Addict
 
Registered: Dec 2013
Posts: 19,872
Blog Entries: 12

Rep: Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053
Could also be some config thing on the client side.

Try to work around it by defining a banner file without invalid characters?
 
Old 05-14-2020, 04:59 PM   #3
fat256
LQ Newbie
 
Registered: May 2020
Posts: 5

Original Poster
Rep: Reputation: Disabled
after tried to add banner , i have always same error message.
 
Old 05-14-2020, 05:40 PM   #4
TB0ne
LQ Guru
 
Registered: Jul 2003
Location: Birmingham, Alabama
Distribution: SuSE, RedHat, Slack,CentOS
Posts: 26,705

Rep: Reputation: 7972Reputation: 7972Reputation: 7972Reputation: 7972Reputation: 7972Reputation: 7972Reputation: 7972Reputation: 7972Reputation: 7972Reputation: 7972Reputation: 7972
Quote:
Originally Posted by fat256 View Post
after tried to add banner , i have always same error message.
Seen it before, and ondoho is right; it's a client side thing. By any chance, do you have root logins disabled, and do you have any cron jobs doing rsync/network backups?? Sometimes network scans can trigger that (browsers, bots, etc.), or it could be someone probing your system. Or just an rsync job running over SSH that's causing it. Several things can make it pop up, but without knowing more about the server, where it is, what it does, and what's connected to/accessing it, it's hard to pinpoint.
 
Old 05-14-2020, 06:12 PM   #5
fat256
LQ Newbie
 
Registered: May 2020
Posts: 5

Original Poster
Rep: Reputation: Disabled
good idea , i reused an existing IP , how i could know which client ( found IP ) is trying to communicate with system ?
I have no cron configured , it is a fresh install .
 
Old 05-14-2020, 06:58 PM   #6
fat256
LQ Newbie
 
Registered: May 2020
Posts: 5

Original Poster
Rep: Reputation: Disabled
with tcpdump i found the ip.
thanks ,
 
Old 05-16-2020, 02:13 AM   #7
ondoho
LQ Addict
 
Registered: Dec 2013
Posts: 19,872
Blog Entries: 12

Rep: Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053
Quote:
Originally Posted by fat256 View Post
after tried to add banner , i have always same error message.
I wonder where you added what file with what content.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Starting sshd: /etc/init.d/sshd: line 113: /usr/sbin/sshd: Permission denied sumanc Linux - Server 5 03-28-2008 04:59 AM
FC4-Starting sshd: Privilege separation user sshd does not exist FAILED kiranherekar Fedora 5 12-29-2005 02:22 PM
How to change ssh banner in sshd.config pAn1k Linux - Networking 2 03-24-2005 04:46 PM
Enabling SSH in mandrake 9.2 - sshd vs. sshd-xinetd DogTags Linux - Newbie 7 11-25-2003 12:17 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > CentOS

All times are GMT -5. The time now is 02:43 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration