Subject: SSH question: What does "Corrupted HMAC on input" mean?
To: None <tech-security@netbsd.org>
From: Brian Chase <bdc@world.std.com>
List: tech-security
Date: 01/28/2001 11:10:56
When I try to connect from a new NetBSD/i386 box to some of our servers
which run sshd, I get the following error message.  The SSH installation
on the server was installed from binary package for Solaris x86 8.0
available on the net (not my idea).

  client% ssh server
  Disconnecting: Corrupted HMAC on input.
  %

Is this a just a bug, or is this something I should be concerned about?

On the client side (NetBSD/i386 1.5).

  client% ssh -v
  SSH Version OpenSSH_2.2.0 NetBSD_Secure_Shell-20001003, \
    protocol versions 1.5/2.0.
  Compiled with OpenSSL (0x0090581f).
  [...]

On the server side (Solaris x86 8.0).

  server% sshd2 -v
  ssh: SSH Secure Shell 2.4.0 (non-commercial version) on i386-pc-solaris2.8
  [...]


-brian.
--- Brian Chase | bdc@world.std.com | http://world.std.com/~bdc/ -----
                        DOUBLE YOU AITCH WHY