<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[AD users SSH connection not working]]></title><description><![CDATA[<p dir="auto">Hello,</p>
<p dir="auto">SSH is enabled, the AD users belong to the group <strong>pfSense</strong> and the group <strong>pfSense</strong> has following privileges.</p>
<ul>
<li>
<p dir="auto">WebCfg - All pages: Allow access to all pages</p>
</li>
<li>
<p dir="auto">User - System: Shell account access: Indicates whether the user is able to login for example via SSH.</p>
</li>
<li>
<p dir="auto">User - System: SSH tunneling Indicates whether the user is able to login for tunneling via SSH when they have no shell access. Note: User - System - Copy files conflicts with this privilege.</p>
</li>
</ul>
<p dir="auto">If I try to access pfSense via SSH, I get the error message, that my password is wrong. The <strong>logs</strong> include following entries.</p>
<pre><code>Sep 8 12:00:43 	sshd 	24523 	Invalid user USERNAME from x.x.x.x
Sep 8 12:00:43 	sshd 	24523 	input_userauth_request: invalid user USERNAME [preauth]
Sep 8 12:00:43 	sshd 	24523 	Postponed keyboard-interactive for invalid user USERNAME from x.x.x.x port 49783 ssh2 [preauth]
Sep 8 12:00:47 	sshd 	24523 	error: PAM: authentication error for illegal user USERNAME from x.x.x.x
Sep 8 12:00:47 	sshd 	24523 	Failed keyboard-interactive/pam for invalid user USERNAME from x.x.x.x port 49783 ssh2 
</code></pre>
<p dir="auto">What is going wrong? Thank you in advance!</p>
<p dir="auto">Kind regards,<br />
vrugaitis</p>
]]></description><link>https://forum.netgate.com/topic/120065/ad-users-ssh-connection-not-working</link><generator>RSS for Node</generator><lastBuildDate>Mon, 09 Mar 2026 08:16:53 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/120065.rss" rel="self" type="application/rss+xml"/><pubDate>Fri, 08 Sep 2017 11:45:29 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to AD users SSH connection not working on Fri, 08 Sep 2017 15:17:07 GMT]]></title><description><![CDATA[<p dir="auto">It's not on anyone's radar or to-do list that I'm aware of.</p>
]]></description><link>https://forum.netgate.com/post/720633</link><guid isPermaLink="true">https://forum.netgate.com/post/720633</guid><dc:creator><![CDATA[jimp]]></dc:creator><pubDate>Fri, 08 Sep 2017 15:17:07 GMT</pubDate></item><item><title><![CDATA[Reply to AD users SSH connection not working on Fri, 08 Sep 2017 15:15:02 GMT]]></title><description><![CDATA[<p dir="auto">Thank you for the fast reply! Is this functionality on the roadmap or does it have such a low priority, that it is unlikely to come?</p>
]]></description><link>https://forum.netgate.com/post/720632</link><guid isPermaLink="true">https://forum.netgate.com/post/720632</guid><dc:creator><![CDATA[vrugaitis]]></dc:creator><pubDate>Fri, 08 Sep 2017 15:15:02 GMT</pubDate></item><item><title><![CDATA[Reply to AD users SSH connection not working on Fri, 08 Sep 2017 14:22:46 GMT]]></title><description><![CDATA[<p dir="auto">There is no mechanism in place to allow RADIUS or LDAP users to connect to ssh at this time. The authentication works only for the GUI itself and other areas that use the same mechanisms to authenticate (e.g. VPNs)</p>
]]></description><link>https://forum.netgate.com/post/720622</link><guid isPermaLink="true">https://forum.netgate.com/post/720622</guid><dc:creator><![CDATA[jimp]]></dc:creator><pubDate>Fri, 08 Sep 2017 14:22:46 GMT</pubDate></item><item><title><![CDATA[Reply to AD users SSH connection not working on Fri, 08 Sep 2017 13:07:57 GMT]]></title><description><![CDATA[<p dir="auto">Hello,</p>
<p dir="auto">here are the answers to your questions.</p>
<blockquote>
<p dir="auto">What pfSense version ?</p>
</blockquote>
<p dir="auto">2.3.4-RELEASE-p1 (amd64)<br />
built on Fri Jul 14 14:52:43 CDT 2017<br />
FreeBSD 10.3-RELEASE-p19</p>
<blockquote>
<p dir="auto">What SSH client</p>
</blockquote>
<p dir="auto">macOS Sierra<br />
OpenSSH_7.4p1, LibreSSL 2.5.0</p>
<blockquote>
<p dir="auto">Use the login "admin" and the password that goes with it.</p>
<p dir="auto">Now that works ?</p>
</blockquote>
<p dir="auto">Login via root works without any problems.</p>
<blockquote>
<p dir="auto">Btw : If you want to say that AD = Active Directory, then I'm out of ideas.</p>
</blockquote>
<p dir="auto">Your prediction is correct. So basically, root connection via SSH is working, the AD users can't connect via SSH, although they have the right priviledge. But the AD user are able to login to the webGUI. So the authentication via the Active Directory Domain Controller seems to work properly.</p>
<p dir="auto">Do you have any other ideas?</p>
<p dir="auto">Kind regards,<br />
vrugaitis</p>
]]></description><link>https://forum.netgate.com/post/720614</link><guid isPermaLink="true">https://forum.netgate.com/post/720614</guid><dc:creator><![CDATA[vrugaitis]]></dc:creator><pubDate>Fri, 08 Sep 2017 13:07:57 GMT</pubDate></item><item><title><![CDATA[Reply to AD users SSH connection not working on Fri, 08 Sep 2017 12:57:23 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/vrugaitis">@<bdi>vrugaitis</bdi></a>:</p>
<blockquote>
<p dir="auto">SSH is enabled, the AD users ….</p>
</blockquote>
<p dir="auto">AD - what AD ?</p>
<p dir="auto">First things first :<br />
What pfSense version ? (ancient build-in (pfSEnse) openssl libraries wont work at all with recent SSH clients)<br />
What SSH client (saw to many people trying to use Putty installed 6 years ago -  that won't work neither)<br />
Use the login "admin" and the password that goes with it.</p>
<p dir="auto">Now that works ?</p>
<p dir="auto">Btw : If you want to say that AD = Active Directory, then I'm out of ideas.</p>
]]></description><link>https://forum.netgate.com/post/720611</link><guid isPermaLink="true">https://forum.netgate.com/post/720611</guid><dc:creator><![CDATA[Gertjan]]></dc:creator><pubDate>Fri, 08 Sep 2017 12:57:23 GMT</pubDate></item></channel></rss>