Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- MacBook-Pro-Vladimir:~ vladimir$ pkcs11-tool -lO
- Using slot 0 with a present token (0x0)
- Logging in to "Beshelmek".
- Please enter User PIN:
- Public Key Object; RSA 2048 bits
- label:
- ID: 45
- Usage: encrypt, verify, wrap
- Private Key Object; RSA
- label:
- ID: 45
- Usage: decrypt, sign, unwrap
- MacBook-Pro-Vladimir:~ vladimir$ cat .ssh/config
- Host *
- PKCS11Provider /usr/local/lib/librtpkcs11ecp.dylib
- MacBook-Pro-Vladimir:~ vladimir$ pkcs11-tool -lL
- Available slots:
- Slot 0 (0x0): Aktiv Rutoken ECP
- token label : Beshelmek
- token manufacturer : Aktiv Co.
- token model : Rutoken ECP
- token flags : login required, rng, token initialized, PIN initialized
- hardware version : 20.5
- firmware version : 23.2
- serial num : 3ace6881
- pin min/max : 6/32
- Slot 1 (0x1):
- (empty)
- Slot 2 (0x2):
- (empty)
- Slot 3 (0x3):
- (empty)
- Slot 4 (0x4):
- (empty)
- Slot 5 (0x5):
- (empty)
- Slot 6 (0x6):
- (empty)
- Slot 7 (0x7):
- (empty)
- Slot 8 (0x8):
- (empty)
- Slot 9 (0x9):
- (empty)
- Slot 10 (0xa):
- (empty)
- Slot 11 (0xb):
- (empty)
- Slot 12 (0xc):
- (empty)
- Slot 13 (0xd):
- (empty)
- Slot 14 (0xe):
- (empty)
- MacBook-Pro-Vladimir:~ vladimir$ ssh-keygen -D /usr/local/lib/librtpkcs11ecp.dylib -I 0:45
- ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABAQCkBxrWUyb27RJndi3MkYJAcNurm0FJSwTszgXqs5odFxAmJs7jNH8W+b8pJHLo/nijimxnKDHs5wPPP0v9hSNhHAHXqGtf2Efflm7eVcey8YYYOSxB7ciqGe7f2zTFUPnQC9w1HJ4nxmsZf/gxEDt+DZLtdHEie5R53NL4MdzuCYSzIxQjfYUSHjI4mQLbUl0zsTLWuTpYi1yLwfjom+Ef4UNxSpsMr+6y4lWwEGi6XqFMAQZXRQASjsRRrs2gvSuY9PjmAIL1BnLHM04rqj9YPrNGyqmTRqUH0nhtX3x37Lz+7F9lpnJjOLAmHmUo3RygUuwAF12zplzTVDC+x067
- MacBook-Pro-Vladimir:~ vladimir$ ssh -vvv [email protected]
- OpenSSH_7.9p1, LibreSSL 2.7.3
- debug1: Reading configuration data /Users/vladimir/.ssh/config
- debug1: /Users/vladimir/.ssh/config line 1: Applying options for *
- debug1: Reading configuration data /etc/ssh/ssh_config
- debug1: /etc/ssh/ssh_config line 48: Applying options for *
- debug2: resolving "beshelmek.org" port 22
- debug2: ssh_connect_direct
- debug1: Connecting to beshelmek.org [172.17.0.1] port 22.
- debug1: Connection established.
- debug1: provider /usr/local/lib/librtpkcs11ecp.dylib: manufacturerID <Aktiv Co.> cryptokiVersion 2.20 libraryDescription <Rutoken ECP PKCS #11 library> libraryVersion 1.9
- debug1: provider /usr/local/lib/librtpkcs11ecp.dylib slot 0: label <Beshelmek> manufacturerID <Aktiv Co.> model <Rutoken ECP> serial <3ace6881> flags 0x40d
- debug1: have 1 keys
- debug1: identity file /Users/vladimir/.ssh/id_rsa type -1
- debug1: identity file /Users/vladimir/.ssh/id_rsa-cert type -1
- debug1: identity file /Users/vladimir/.ssh/id_dsa type -1
- debug1: identity file /Users/vladimir/.ssh/id_dsa-cert type -1
- debug1: identity file /Users/vladimir/.ssh/id_ecdsa type -1
- debug1: identity file /Users/vladimir/.ssh/id_ecdsa-cert type -1
- debug1: identity file /Users/vladimir/.ssh/id_ed25519 type -1
- debug1: identity file /Users/vladimir/.ssh/id_ed25519-cert type -1
- debug1: identity file /Users/vladimir/.ssh/id_xmss type -1
- debug1: identity file /Users/vladimir/.ssh/id_xmss-cert type -1
- debug1: Local version string SSH-2.0-OpenSSH_7.9
- debug1: Remote protocol version 2.0, remote software version OpenSSH_7.4p1 Debian-10+deb9u5
- debug1: match: OpenSSH_7.4p1 Debian-10+deb9u5 pat OpenSSH_7.0*,OpenSSH_7.1*,OpenSSH_7.2*,OpenSSH_7.3*,OpenSSH_7.4*,OpenSSH_7.5*,OpenSSH_7.6*,OpenSSH_7.7* compat 0x04000002
- debug2: fd 5 setting O_NONBLOCK
- debug1: Authenticating to beshelmek.org:22 as 'root'
- debug3: hostkeys_foreach: reading file "/Users/vladimir/.ssh/known_hosts"
- debug3: record_hostkey: found key type ECDSA in file /Users/vladimir/.ssh/known_hosts:4
- debug3: load_hostkeys: loaded 1 keys from beshelmek.org
- debug3: hostkeys_foreach: reading file "/Users/vladimir/.ssh/known_hosts2"
- debug3: record_hostkey: found key type ECDSA in file /Users/vladimir/.ssh/known_hosts2:4
- debug3: record_hostkey: found key type ECDSA in file /Users/vladimir/.ssh/known_hosts2:53
- debug3: record_hostkey: found key type ECDSA in file /Users/vladimir/.ssh/known_hosts2:91
- debug3: record_hostkey: found key type ECDSA in file /Users/vladimir/.ssh/known_hosts2:119
- debug3: record_hostkey: found key type ECDSA in file /Users/vladimir/.ssh/known_hosts2:142
- debug3: record_hostkey: found key type ECDSA in file /Users/vladimir/.ssh/known_hosts2:159
- debug3: record_hostkey: found key type ECDSA in file /Users/vladimir/.ssh/known_hosts2:174
- debug3: load_hostkeys: loaded 7 keys from beshelmek.org
- debug3: order_hostkeyalgs: prefer hostkeyalgs: [email protected],[email protected],[email protected],ecdsa-sha2-nistp256,ecdsa-sha2-nistp384,ecdsa-sha2-nistp521
- debug3: send packet: type 20
- debug1: SSH2_MSG_KEXINIT sent
- debug3: receive packet: type 20
- debug1: SSH2_MSG_KEXINIT received
- debug2: local client KEXINIT proposal
- debug2: KEX algorithms: curve25519-sha256,[email protected],ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256,diffie-hellman-group14-sha1,ext-info-c
- debug2: host key algorithms: [email protected],[email protected],[email protected],ecdsa-sha2-nistp256,ecdsa-sha2-nistp384,ecdsa-sha2-nistp521,[email protected],[email protected],[email protected],[email protected],ssh-ed25519,rsa-sha2-512,rsa-sha2-256,ssh-rsa
- debug2: ciphers ctos: [email protected],aes128-ctr,aes192-ctr,aes256-ctr,[email protected],[email protected]
- debug2: ciphers stoc: [email protected],aes128-ctr,aes192-ctr,aes256-ctr,[email protected],[email protected]
- debug2: MACs ctos: [email protected],[email protected],[email protected],[email protected],[email protected],[email protected],[email protected],hmac-sha2-256,hmac-sha2-512,hmac-sha1
- debug2: MACs stoc: [email protected],[email protected],[email protected],[email protected],[email protected],[email protected],[email protected],hmac-sha2-256,hmac-sha2-512,hmac-sha1
- debug2: compression ctos: none,[email protected],zlib
- debug2: compression stoc: none,[email protected],zlib
- debug2: languages ctos:
- debug2: languages stoc:
- debug2: first_kex_follows 0
- debug2: reserved 0
- debug2: peer server KEXINIT proposal
- debug2: KEX algorithms: curve25519-sha256,[email protected],ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256,diffie-hellman-group14-sha1
- debug2: host key algorithms: ssh-rsa,rsa-sha2-512,rsa-sha2-256,ecdsa-sha2-nistp256,ssh-ed25519
- debug2: ciphers ctos: [email protected],aes128-ctr,aes192-ctr,aes256-ctr,[email protected],[email protected]
- debug2: ciphers stoc: [email protected],aes128-ctr,aes192-ctr,aes256-ctr,[email protected],[email protected]
- debug2: MACs ctos: [email protected],[email protected],[email protected],[email protected],[email protected],[email protected],[email protected],hmac-sha2-256,hmac-sha2-512,hmac-sha1
- debug2: MACs stoc: [email protected],[email protected],[email protected],[email protected],[email protected],[email protected],[email protected],hmac-sha2-256,hmac-sha2-512,hmac-sha1
- debug2: compression ctos: none,[email protected]
- debug2: compression stoc: none,[email protected]
- debug2: languages ctos:
- debug2: languages stoc:
- debug2: first_kex_follows 0
- debug2: reserved 0
- debug1: kex: algorithm: curve25519-sha256
- debug1: kex: host key algorithm: ecdsa-sha2-nistp256
- debug1: kex: server->client cipher: [email protected] MAC: <implicit> compression: none
- debug1: kex: client->server cipher: [email protected] MAC: <implicit> compression: none
- debug3: send packet: type 30
- debug1: expecting SSH2_MSG_KEX_ECDH_REPLY
- debug3: receive packet: type 31
- debug1: Server host key: ecdsa-sha2-nistp256 SHA256:AwLHKbATV9hpEv71Xb09BHH1m6RKDRCoEFtiZpexXKg
- debug3: hostkeys_foreach: reading file "/Users/vladimir/.ssh/known_hosts"
- debug3: record_hostkey: found key type ECDSA in file /Users/vladimir/.ssh/known_hosts:4
- debug3: load_hostkeys: loaded 1 keys from beshelmek.org
- debug3: hostkeys_foreach: reading file "/Users/vladimir/.ssh/known_hosts2"
- debug3: record_hostkey: found key type ECDSA in file /Users/vladimir/.ssh/known_hosts2:4
- debug3: record_hostkey: found key type ECDSA in file /Users/vladimir/.ssh/known_hosts2:53
- debug3: record_hostkey: found key type ECDSA in file /Users/vladimir/.ssh/known_hosts2:91
- debug3: record_hostkey: found key type ECDSA in file /Users/vladimir/.ssh/known_hosts2:119
- debug3: record_hostkey: found key type ECDSA in file /Users/vladimir/.ssh/known_hosts2:142
- debug3: record_hostkey: found key type ECDSA in file /Users/vladimir/.ssh/known_hosts2:159
- debug3: record_hostkey: found key type ECDSA in file /Users/vladimir/.ssh/known_hosts2:174
- debug3: load_hostkeys: loaded 7 keys from beshelmek.org
- debug3: hostkeys_foreach: reading file "/Users/vladimir/.ssh/known_hosts"
- debug3: record_hostkey: found key type ECDSA in file /Users/vladimir/.ssh/known_hosts:14
- debug3: load_hostkeys: loaded 1 keys from 172.17.0.1
- debug3: hostkeys_foreach: reading file "/Users/vladimir/.ssh/known_hosts2"
- debug3: record_hostkey: found key type ECDSA in file /Users/vladimir/.ssh/known_hosts2:14
- debug3: record_hostkey: found key type ECDSA in file /Users/vladimir/.ssh/known_hosts2:63
- debug3: record_hostkey: found key type ECDSA in file /Users/vladimir/.ssh/known_hosts2:102
- debug3: record_hostkey: found key type ECDSA in file /Users/vladimir/.ssh/known_hosts2:130
- debug3: record_hostkey: found key type ECDSA in file /Users/vladimir/.ssh/known_hosts2:153
- debug3: record_hostkey: found key type ECDSA in file /Users/vladimir/.ssh/known_hosts2:170
- debug3: load_hostkeys: loaded 6 keys from 172.17.0.1
- debug1: Host 'beshelmek.org' is known and matches the ECDSA host key.
- debug1: Found key in /Users/vladimir/.ssh/known_hosts:4
- debug3: send packet: type 21
- debug2: set_newkeys: mode 1
- debug1: rekey after 134217728 blocks
- debug1: SSH2_MSG_NEWKEYS sent
- debug1: expecting SSH2_MSG_NEWKEYS
- debug3: receive packet: type 21
- debug1: SSH2_MSG_NEWKEYS received
- debug2: set_newkeys: mode 0
- debug1: rekey after 134217728 blocks
- debug1: Will attempt key: /usr/local/lib/librtpkcs11ecp.dylib RSA SHA256:5HRoCccbOqdC+QqToOqIM8LTgdaG93Hy7UavOgcPoSg token
- debug1: Will attempt key: /Users/vladimir/.ssh/id_rsa
- debug1: Will attempt key: /Users/vladimir/.ssh/id_dsa
- debug1: Will attempt key: /Users/vladimir/.ssh/id_ecdsa
- debug1: Will attempt key: /Users/vladimir/.ssh/id_ed25519
- debug1: Will attempt key: /Users/vladimir/.ssh/id_xmss
- debug2: pubkey_prepare: done
- debug3: send packet: type 5
- debug3: receive packet: type 7
- debug1: SSH2_MSG_EXT_INFO received
- debug1: kex_input_ext_info: server-sig-algs=<ssh-ed25519,ssh-rsa,ssh-dss,ecdsa-sha2-nistp256,ecdsa-sha2-nistp384,ecdsa-sha2-nistp521>
- debug3: receive packet: type 6
- debug2: service_accept: ssh-userauth
- debug1: SSH2_MSG_SERVICE_ACCEPT received
- debug3: send packet: type 50
- debug3: receive packet: type 51
- debug1: Authentications that can continue: publickey,password
- debug3: start over, passed a different list publickey,password
- debug3: preferred publickey,keyboard-interactive,password
- debug3: authmethod_lookup publickey
- debug3: remaining preferred: keyboard-interactive,password
- debug3: authmethod_is_enabled publickey
- debug1: Next authentication method: publickey
- debug1: Offering public key: /usr/local/lib/librtpkcs11ecp.dylib RSA SHA256:5HRoCccbOqdC+QqToOqIM8LTgdaG93Hy7UavOgcPoSg token
- debug3: send packet: type 50
- debug2: we sent a publickey packet, wait for reply
- debug3: receive packet: type 51
- debug1: Authentications that can continue: publickey,password
- debug1: Trying private key: /Users/vladimir/.ssh/id_rsa
- debug3: no such identity: /Users/vladimir/.ssh/id_rsa: No such file or directory
- debug1: Trying private key: /Users/vladimir/.ssh/id_dsa
- debug3: no such identity: /Users/vladimir/.ssh/id_dsa: No such file or directory
- debug1: Trying private key: /Users/vladimir/.ssh/id_ecdsa
- debug3: no such identity: /Users/vladimir/.ssh/id_ecdsa: No such file or directory
- debug1: Trying private key: /Users/vladimir/.ssh/id_ed25519
- debug3: no such identity: /Users/vladimir/.ssh/id_ed25519: No such file or directory
- debug1: Trying private key: /Users/vladimir/.ssh/id_xmss
- debug3: no such identity: /Users/vladimir/.ssh/id_xmss: No such file or directory
- debug2: we did not send a packet, disable method
- debug3: authmethod_lookup password
- debug3: remaining preferred: ,password
- debug3: authmethod_is_enabled password
- debug1: Next authentication method: password
- [email protected]'s password:
Advertisement
Add Comment
Please, Sign In to add comment