2017-03-07 2 views
1

Ich habe zwei EC2-Instanzen in einer VPC - eine Bastion und Dev-Maschine.ssh zwischen Amazon EC2-Instanzen mit X11-Weiterleitung

Ich kann ssh in die Bastion und X11-Anwendungen ausführen. Wenn ich jedoch von der Bastion zum Dev-Rechner schalte, schlägt die X-Weiterleitung fehl:

> ssh -vX -i ~/.ssh/my_key.pem [email protected] 
… 
debug1: Requesting X11 forwarding with authentication spoofing. 
debug1: Sending environment. 
debug1: Sending env LANG = en_US.UTF-8 
debug1: Remote: Can't get IP address for X11 DISPLAY. 
X11 forwarding request failed on channel 0 

Das vollständige Protokoll ist unten. (. Dh die Dev-Maschine)

Die Remote-Instanz hat das xauth-Paket installiert, und die/etc/ssh/sshd_config-Datei (auf der Dev-Maschine) die folgenden Einträge:

X11Forwarding yes 
X11UseLocalhost no 

Weiß jemand, Was könnte das Problem sein?

prost steve

OpenSSH_6.6.1, OpenSSL 1.0.1e-fips 11 Feb 2013 
debug1: Reading configuration data /etc/ssh/ssh_config 
debug1: /etc/ssh/ssh_config line 56: Applying options for * 
debug1: Connecting to X.X.X.X [X.X.X.X] port 22. 
debug1: Connection established. 
debug1: identity file /home/ec2-user/.ssh/my_key.pem type -1 
debug1: identity file /home/ec2-user/.ssh/my_key.pem-cert type -1 
debug1: Enabling compatibility mode for protocol 2.0 
debug1: Local version string SSH-2.0-OpenSSH_6.6.1 
debug1: Remote protocol version 2.0, remote software version OpenSSH_6.6.1 
debug1: match: OpenSSH_6.6.1 pat OpenSSH_6.6.1* compat 0x04000000 
debug1: SSH2_MSG_KEXINIT sent 
debug1: SSH2_MSG_KEXINIT received 
debug1: kex: server->client aes128-ctr [email protected] none 
debug1: kex: client->server aes128-ctr [email protected] none 
debug1: kex: [email protected] need=16 dh_need=16 
debug1: kex: [email protected] need=16 dh_need=16 
debug1: sending SSH2_MSG_KEX_ECDH_INIT 
debug1: expecting SSH2_MSG_KEX_ECDH_REPLY 
debug1: Server host key: ECDSA Y:Y:Y:Y:Y:Y:Y:Y:Y 
debug1: Host 'X.X.X.X' is known and matches the ECDSA host key. 
debug1: Found key in /home/ec2-user/.ssh/known_hosts:1 
debug1: ssh_ecdsa_verify: signature correct 
debug1: SSH2_MSG_NEWKEYS sent 
debug1: expecting SSH2_MSG_NEWKEYS 
debug1: SSH2_MSG_NEWKEYS received 
debug1: Roaming not allowed by server 
debug1: SSH2_MSG_SERVICE_REQUEST sent 
debug1: SSH2_MSG_SERVICE_ACCEPT received 
debug1: Authentications that can continue: publickey 
debug1: Next authentication method: publickey 
debug1: Trying private key: /home/ec2-user/.ssh/my_key.pem 
debug1: key_parse_private2: missing begin marker 
debug1: read PEM private key done: type RSA 
debug1: Authentication succeeded (publickey). 
Authenticated to X.X.X.X ([X.X.X.X]:22). 
debug1: channel 0: new [client-session] 
debug1: Requesting [email protected] 
debug1: Entering interactive session. 
debug1: Requesting X11 forwarding with authentication spoofing. 
debug1: Sending environment. 
debug1: Sending env LANG = en_US.UTF-8 
debug1: Remote: Can't get IP address for X11 DISPLAY. 
X11 forwarding request failed on channel 0 

Antwort

0

Die Lösung war X11UseLocalhost auf "Ja" zu setzen.

Verwandte Themen