Trying to connect to a linux machine running SuSE, with
OpenSSH 3.7.1p2 (original SuSE RPM), sshVNC crashes
with a NullPointerException, as quoted below.
This only occurs if /etc/ssh/sshd_config is unmodified.
By setting
PasswordAuthentication yes
..SshVNC can connect just fine. That indicates
something in the keyboard-interactive-code in SSHVnc is
buggy.
The client first asks me what authentication methods to
proceed with, I then select "keyboard-interactive" and
press "Proceed". It pops up a dialog where I enter my
password ("test") and then it crashes with the
NullPointerException below in the Java Console.
INFO: Requesting authentication methods
Creating prompt Password: and setting to null
Setting reply 0 to test
java.lang.NullPointerException at
com.sshtools.common.authentication.KBIRequestHandlerDialog.showPrompts(Unknown
Source)
at
com.sshtools.j2ssh.authentication.KBIAuthenticationClient.authenticate(Unknown
Source)
at
com.sshtools.j2ssh.authentication.AuthenticationProtocolClient.authenticate(Unknown
Source)
at com.sshtools.j2ssh.SshClient.authenticate(Unknown
Source)
at
com.sshtools.sshvnc.SshVNCPanel.showAuthenticationPrompt(Unknown
Source)
at
com.sshtools.common.ui.SshToolsApplicationClientPanel.authenticateUser(Unknown
Source)
at
com.sshtools.common.ui.SshToolsApplicationClientPanel$1.run(Unknown
Source)
at java.lang.Thread.run(Unknown Source)
The ssh daemon on the server seems to send not a
SSH_MSG_USERAUTH_SUCCESS but a
SSH_MSG_USERAUTH_INFO_REQUEST to the client, even
though it is really a success. I think there might
come a SUCCESS message after the INFO_REQUEST, but
since SSHVnc crashes, it never gets that.
The problem seems to be related to the "instruction"
field being null, or something like that.
If supplying an incorrect password, the server sends a
SSH_MSG_USERAUTH_FAILURE and SSHVnc pops up the
password dialog again.
Logged In: YES
user_id=311961
The behaviour by the server (sending a INFO_REQUEST even
though the authentication succeeded, then sending a success
message after a small delay) is totally in compliance with
RFC4256.
Attaching a patch that corrects problem.
Patch to KBIAuthenticationClient.java to correct problem.