Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    SSH inaccessibleupdate to version 25.07

    Scheduled Pinned Locked Moved General pfSense Questions
    21 Posts 3 Posters 9.2k Views 3 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • stephenw10S Offline
      stephenw10 Netgate Administrator
      last edited by

      Like an actual unexpected change in the config?

      A 1 Reply Last reply Reply Quote 0
      • A Offline
        alvescaio @stephenw10
        last edited by

        @stephenw10 said in SSH inaccessibleupdate to version 25.07:

        Like an actual unexpected change in the config?

        Exactly, I did a "from to" from an old version of pfsense and verified that the sheldo access role for my user caio.chagas was automatically removed, and curiously after I assigned the role again, access via WEB via C2S VPN stopped.

        1 Reply Last reply Reply Quote 0
        • stephenw10S Offline
          stephenw10 Netgate Administrator
          last edited by

          Do you have Nexus/MIM enabled?

          A 1 Reply Last reply Reply Quote 0
          • A Offline
            alvescaio @stephenw10
            last edited by

            @stephenw10 Not, Strange, I still can't access via SSH, and as the other friend said, I can't see any public key loaded in the login.

            1 Reply Last reply Reply Quote 0
            • stephenw10S Offline
              stephenw10 Netgate Administrator
              last edited by

              The public key for users would be in the config. Did that also get removed?

              To be clear, you don't have Nexus enabled?

              A 1 Reply Last reply Reply Quote 0
              • A Offline
                alvescaio @stephenw10
                last edited by

                @stephenw10 said in SSH inaccessibleupdate to version 25.07:

                The public key for users would be in the config. Did that also get removed?

                To be clear, you don't have Nexus enabled?

                I haven't enabled Nexus, and I don't even know what it is. I only see the public key in the admin user, not in my user. But in pfsense antido, I only see the public key in the admin user and not in my user, and I can connect.

                A 1 Reply Last reply Reply Quote 0
                • stephenw10S Offline
                  stephenw10 Netgate Administrator
                  last edited by

                  You absolutely should see the public key in the config like:

                  		<user>
                  			<scope>user</scope>
                  			<bcrypt-hash>$xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx</bcrypt-hash>
                  			<descr></descr>
                  			<name>test</name>
                  			<expires></expires>
                  			<dashboardcolumns>2</dashboardcolumns>
                  			<authorizedkeys>xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxbase64encodedkeyherexxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx</authorizedkeys>
                  			<ipsecpsk></ipsecpsk>
                  			<webguicss>pfSense.css</webguicss>
                  			<keephistory></keephistory>
                  			<uid>2011</uid>
                  			<priv>user-shell-access</priv>
                  		</user>
                  

                  You should also be able to see it in the webgui for that user.

                  1 Reply Last reply Reply Quote 0
                  • A Offline
                    alvescaio @alvescaio
                    last edited by

                    Another point I noticed, is that after the update, users who have access permission via secure shell automatically lost it and after I reassigned access via VPN, that is, access via LAN interface via VPN C2S in the web GUI stopped, only access via WAN, public IP is functional

                    1 Reply Last reply Reply Quote 0
                    • stephenw10S Offline
                      stephenw10 Netgate Administrator
                      last edited by

                      Are you able to replicate that? If you roll back to 24.11 and upgrade again?

                      So far I've failed to replicate it.

                      A 1 Reply Last reply Reply Quote 0
                      • A Offline
                        alvescaio @stephenw10
                        last edited by

                        @stephenw10 said in SSH inaccessibleupdate to version 25.07:

                        Are you able to replicate that? If you roll back to 24.11 and upgrade again?

                        So far I've failed to replicate it.

                        Então, eu tenho um cluster, e o secundário é em 24.11 e não tem esse problema. Não sei se informei masperceboq ue como se o servo do opevpn travasse e quando eu resetei o serviço doprofile que estou utilizando ele volta a funcionar.

                        1 Reply Last reply Reply Quote 0
                        • stephenw10S Offline
                          stephenw10 Netgate Administrator
                          last edited by

                          So you upgraded the secondary to 25.07 and it didn't hit the same issue?

                          1 Reply Last reply Reply Quote 0
                          • First post
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.