RSA Authentication Manager 8.2 customized SSH logon banner is not displayed
Originally Published: 2017-03-10
Article Number
Applies To
RSA Product/Service Type : RSA Authentication Manager
RSA Version/Condition: 8.2
Issue
An administrator has followed the steps to update /opt/rsa/am/utils/etc/ssh-banner-sample to customize the display (see "How To Configure a Custom SSH Logon Banner" on page 141 of the RSA Authentication Manager 8.2 Administrator’s Guide ),but the new banner is not displayed during the start of an SSH session.
Cause
Resolution
Steps
- Launch the SSH client and connect to the appliance using the IP address or fully qualified hostname.
- When prompted, type the operating system user ID of rsaadmin, and press Enter.
- When prompted, type the password for the rsaadmin operating system account, and press Enter.
- Change the privileges of the rsaadmin account using the command sudo su - root.
- When prompted, type the password for the rsaadmin operating system account, and press Enter.
- Navigate to /etc/ssh/ and press Enter.
- Open the sshd_config file in a text editor.
login as: rsaadmin Using keyboard-interactive authentication. Password: <enter operating system password> Last login: Mon Mar 13 16:19:24 2017 from jumphost.vcloud.local RSA Authentication Manager Installation Directory: /opt/rsa/am rsaadmin@am82p:~> sudo su - root rsaadmin's password: <enter operating system password> am82p:~ # cd /etc/ssh/ am82p:/etc/ssh # vi sshd_config
- Search for the keyword Banner.
# Example of overriding settings on a per-user basis #Match User anoncvs # X11Forwarding no # AllowTcpForwarding no # ForceCommand cvs server AllowUsers rsaadmin /Banner
- Add or change the line to what is shown here:
... ... # no default banner path Banner /opt/rsa/am/utils/etc/ssh-banner ... ...
- Save the change by typing :wq!
- Restart the sshd service:
service sshd restart
- Confirm that the change took effect by launching the SSH client and connecting to the appliance using the IP address or fully qualified hostname. The updated banner information created in /opt/rsa/am/utils/etc/ssh-banner-sample should display. Here it now reads" Authorized Usage Only - RSA Customer Support."
login as: rsaadmin Using keyboard-interactive authentication. Password: <enter operating system password> Authorized Usage Only - RSA Customer Support Last login: Fri Mar 10 12:12:59 2017 RSA Authentication Manager Installation Directory: /opt/rsa/am rsaadmin@am82p:~>
Related Articles
RSA Authentication Manager 8.2 SP1 Patch 8 Readme 32Number of Views FIM - Can FIM create SAML assertions signed with SHA256 instead of SHA1? 26Number of Views SSH authentication failed for a challenged user with RSA Authentication Manager using REST protocol for RSA Authentication… 453Number of Views RSA Authentication Manager 8.2 SP1 Patch 7 Readme 67Number of Views Troubleshooting 'Administrative Access Denied' error message when scanning target machines using Datacenter 5Number of Views
Trending Articles
RSA Authentication Manager 8.7 SP2 Setup and Configuration Guide RSA MFA Agent 2.5 for Microsoft Windows Installation and Administration Guide How to Upgrade Internal SHA-1 Certificates to SHA-256 in Authentication Manager Using rsautil RSA Release Notes for RSA Authentication Manager 8.8 RSA SecurID Desktop Token 5.0.3 for Windows Administrator's Guide
Don't see what you're looking for?