# SSH Failed to open a secure file transfer session

**URL:** https://forums.suse.com/t/ssh-failed-to-open-a-secure-file-transfer-session/21975
**Category:** SLES Networking
**Created:** [December 4, 2011, 3:56pm UTC](https://forums.suse.com/t/ssh-failed-to-open-a-secure-file-transfer-session/21975 "2011-12-04T15:56:02Z")
**Posts on this page:** 9
**Page:** 1

<div class="post-metadata">

### Author: ![System1](https://avatars.discourse-cdn.com/v4/letter/s/51bf81/32.png) [@System1](https://forums.suse.com/u/System1)
#### Post date: [December 4, 2011, 3:56pm UTC](https://forums.suse.com/t/ssh-failed-to-open-a-secure-file-transfer-session/21975/1 "2011-12-04T15:56:02Z")

</div>

open tcp and udp 22 port.  
use ssh client to download file got this error.  
How can fix it?  
Thanks.

## – hoiyi88

hoiyi88’s Profile: [http://forums.novell.com/member.php?userid=107113](http://forums.novell.com/member.php?userid=107113)  
View this thread: [http://forums.novell.com/showthread.php?t=449083](http://forums.novell.com/showthread.php?t=449083)

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/flex022/uploads/suse/original/2X/5/5012ba89e3ffb5220dac47d5ea0ba032e2fe1cb6.png) [@system](https://forums.suse.com/u/system)
#### Post date: [December 4, 2011, 4:44pm UTC](https://forums.suse.com/t/ssh-failed-to-open-a-secure-file-transfer-session/21975/2 "2011-12-04T16:44:09Z")

</div>

On Sun, 04 Dec 2011 13:56:02 GMT  
hoiyi88 [hoiyi88@no-mx.forums.novell.com](mailto:hoiyi88@no-mx.forums.novell.com) wrote:  
[color=blue]

> open tcp and udp 22 port.  
> use ssh client to download file got this error.  
> How can fix it?  
> Thanks.
> 
> [/color]  
> Hi  
> Did you use YaST Firewall to allow the Secure Shell Server to open the  
> ports? What SLE version?

–  
Cheers Malcolm Â°Â¿Â° (Linux Counter #276890)  
openSUSE 11.4 (x86\_64) Kernel 2.6.37.6-0.9-desktop  
up 3 days 15:42, 5 users, load average: 0.09, 0.12, 0.14  
GPU GeForce 8600 GTS Silent - Driver Version: 290.10

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/flex022/uploads/suse/original/2X/5/5012ba89e3ffb5220dac47d5ea0ba032e2fe1cb6.png) [@system](https://forums.suse.com/u/system)
#### Post date: [December 4, 2011, 4:56pm UTC](https://forums.suse.com/t/ssh-failed-to-open-a-secure-file-transfer-session/21975/3 "2011-12-04T16:56:01Z")

</div>

suse internal firewall disable.  
SLE version 10 SP4

## – hoiyi88

hoiyi88’s Profile: [http://forums.novell.com/member.php?userid=107113](http://forums.novell.com/member.php?userid=107113)  
View this thread: [http://forums.novell.com/showthread.php?t=449083](http://forums.novell.com/showthread.php?t=449083)

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/flex022/uploads/suse/original/2X/5/5012ba89e3ffb5220dac47d5ea0ba032e2fe1cb6.png) [@system](https://forums.suse.com/u/system)
#### Post date: [December 4, 2011, 5:30pm UTC](https://forums.suse.com/t/ssh-failed-to-open-a-secure-file-transfer-session/21975/4 "2011-12-04T17:30:32Z")

</div>

On Sun, 04 Dec 2011 14:56:01 GMT  
hoiyi88 [hoiyi88@no-mx.forums.novell.com](mailto:hoiyi88@no-mx.forums.novell.com) wrote:  
[color=blue]

> suse internal firewall disable.  
> SLE version 10 SP4
> 
> [/color]  
> Hi  
> So are you using the command line of a GUI eg nautilus?

So if you connect vi command line with some debug, can you post the  
output;

```auto
sftp -vv username@host
```

Please put the output around cod tags or on pastebin and post back the  
URL (You might want to edit any security related items, ip address  
etc).

–  
Cheers Malcolm Â°Â¿Â° (Linux Counter #276890)  
openSUSE 11.4 (x86\_64) Kernel 2.6.37.6-0.9-desktop  
up 3 days 16:25, 5 users, load average: 0.08, 0.14, 0.12  
GPU GeForce 8600 GTS Silent - Driver Version: 290.10

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/flex022/uploads/suse/original/2X/5/5012ba89e3ffb5220dac47d5ea0ba032e2fe1cb6.png) [@system](https://forums.suse.com/u/system)
#### Post date: [December 4, 2011, 5:46pm UTC](https://forums.suse.com/t/ssh-failed-to-open-a-secure-file-transfer-session/21975/5 "2011-12-04T17:46:02Z")

</div>

malcolmlewis;2158426 Wrote:[color=blue]

> On Sun, 04 Dec 2011 14:56:01 GMT  
> hoiyi88 [hoiyi88@no-mx.forums.novell.com](mailto:hoiyi88@no-mx.forums.novell.com) wrote:  
> [color=green]
> 
> > suse internal firewall disable.  
> > SLE version 10 SP4
> > 
> > [/color]  
> > Hi  
> > So are you using the command line of a GUI eg nautilus?
> 
> So if you connect vi command line with some debug, can you post the  
> output;[color=green]
> 
> > [/color][/color]  
> > Code:  
> > --------------------[color=blue][color=green]  
> > [/color]  
> > sftp -vv username@host  
> > [/color]  
> > --------------------[color=blue][color=green]  
> > [/color]  
> > Please put the output around cod tags or on pastebin and post back  
> > the  
> > URL (You might want to edit any security related items, ip address  
> > etc).
> 
> –  
> Cheers Malcolm Â°Â¿Â° (Linux Counter #276890)  
> openSUSE 11.4 (x86\_64) Kernel 2.6.37.6-0.9-desktop  
> up 3 days 16:25, 5 users, load average: 0.08, 0.14, 0.12  
> GPU GeForce 8600 GTS Silent - Driver Version: 290.10[/color]

www:~ # sftp -vv [root@127.0.0.1](mailto:root@127.0.0.1)  
Connecting to 127.0.0.1…  
OpenSSH\_5.1p1, OpenSSL 0.9.8a 11 Oct 2005  
debug1: Reading configuration data /etc/ssh/ssh\_config  
debug2: ssh\_connect: needpriv 0  
debug1: Connecting to 127.0.0.1 [127.0.0.1] port 22.  
debug1: Connection established.  
debug1: permanently\_set\_uid: 0/0  
debug1: identity file /root/.ssh/id\_rsa type -1  
debug1: identity file /root/.ssh/id\_dsa type -1  
debug1: Remote protocol version 2.0, remote software version  
OpenSSH\_5.1  
debug1: match: OpenSSH\_5.1 pat OpenSSH\*  
debug1: Enabling compatibility mode for protocol 2.0  
debug1: Local version string SSH-2.0-OpenSSH\_5.1  
debug2: fd 3 setting O\_NONBLOCK  
debug1: SSH2\_MSG\_KEXINIT sent  
debug1: SSH2\_MSG\_KEXINIT received  
debug2: kex\_parse\_kexinit:  
diffie-hellman-group-exchange-sha256,diffie-hellman-group-exchange-sha1,diffie-hellman-group14-sha1,diffie-hellman-group1-sha1  
debug2: kex\_parse\_kexinit: ssh-rsa,ssh-dss  
debug2: kex\_parse\_kexinit:  
aes128-cbc,3des-cbc,blowfish-cbc,cast128-cbc,arcfour128,arcfour256,arcfour,aes192-cbc,aes256-cbc,rijndael-cbc@lysator.liu.se,aes128-ctr,aes192-ctr,aes256-ctr  
debug2: kex\_parse\_kexinit:  
aes128-cbc,3des-cbc,blowfish-cbc,cast128-cbc,arcfour128,arcfour256,arcfour,aes192-cbc,aes256-cbc,rijndael-cbc@lysator.liu.se,aes128-ctr,aes192-ctr,aes256-ctr  
debug2: kex\_parse\_kexinit:  
[hmac-md5,hmac-sha1,umac-64@openssh.com](mailto:hmac-md5,hmac-sha1,umac-64@openssh.com),hmac-ripemd160,hmac-ripemd160@openssh.com,hmac-sha1-96,hmac-md5-96  
debug2: kex\_parse\_kexinit:  
[hmac-md5,hmac-sha1,umac-64@openssh.com](mailto:hmac-md5,hmac-sha1,umac-64@openssh.com),hmac-ripemd160,hmac-ripemd160@openssh.com,hmac-sha1-96,hmac-md5-96  
debug2: kex\_parse\_kexinit: [none,zlib@openssh.com](mailto:none,zlib@openssh.com),zlib  
debug2: kex\_parse\_kexinit: [none,zlib@openssh.com](mailto:none,zlib@openssh.com),zlib  
debug2: kex\_parse\_kexinit:  
debug2: kex\_parse\_kexinit:  
debug2: kex\_parse\_kexinit: first\_kex\_follows 0  
debug2: kex\_parse\_kexinit: reserved 0  
debug2: kex\_parse\_kexinit:  
diffie-hellman-group-exchange-sha256,diffie-hellman-group-exchange-sha1,diffie-hellman-group14-sha1,diffie-hellman-group1-sha1  
debug2: kex\_parse\_kexinit: ssh-rsa,ssh-dss  
debug2: kex\_parse\_kexinit:  
aes128-cbc,3des-cbc,blowfish-cbc,cast128-cbc,arcfour128,arcfour256,arcfour,aes192-cbc,aes256-cbc,rijndael-cbc@lysator.liu.se,aes128-ctr,aes192-ctr,aes256-ctr  
debug2: kex\_parse\_kexinit:  
aes128-cbc,3des-cbc,blowfish-cbc,cast128-cbc,arcfour128,arcfour256,arcfour,aes192-cbc,aes256-cbc,rijndael-cbc@lysator.liu.se,aes128-ctr,aes192-ctr,aes256-ctr  
debug2: kex\_parse\_kexinit:  
[hmac-md5,hmac-sha1,umac-64@openssh.com](mailto:hmac-md5,hmac-sha1,umac-64@openssh.com),hmac-ripemd160,hmac-ripemd160@openssh.com,hmac-sha1-96,hmac-md5-96  
debug2: kex\_parse\_kexinit:  
[hmac-md5,hmac-sha1,umac-64@openssh.com](mailto:hmac-md5,hmac-sha1,umac-64@openssh.com),hmac-ripemd160,hmac-ripemd160@openssh.com,hmac-sha1-96,hmac-md5-96  
debug2: kex\_parse\_kexinit: [none,zlib@openssh.com](mailto:none,zlib@openssh.com)  
debug2: kex\_parse\_kexinit: [none,zlib@openssh.com](mailto:none,zlib@openssh.com)  
debug2: kex\_parse\_kexinit:  
debug2: kex\_parse\_kexinit:  
debug2: kex\_parse\_kexinit: first\_kex\_follows 0  
debug2: kex\_parse\_kexinit: reserved 0  
debug2: mac\_setup: found hmac-md5  
debug1: kex: server-\>client aes128-cbc hmac-md5 none  
debug2: mac\_setup: found hmac-md5  
debug1: kex: client-\>server aes128-cbc hmac-md5 none  
debug1: SSH2\_MSG\_KEX\_DH\_GEX\_REQUEST(1024\<1024\<8192) sent  
debug1: expecting SSH2\_MSG\_KEX\_DH\_GEX\_GROUP  
debug2: dh\_gen\_key: priv key bits set: 129/256  
debug2: bits set: 522/1024  
debug1: SSH2\_MSG\_KEX\_DH\_GEX\_INIT sent  
debug1: expecting SSH2\_MSG\_KEX\_DH\_GEX\_REPLY  
debug2: no key of type 0 for host 127.0.0.1  
debug2: no key of type 2 for host 127.0.0.1  
The authenticity of host ‘127.0.0.1 (127.0.0.1)’ can’t be established.

## – hoiyi88

hoiyi88’s Profile: [http://forums.novell.com/member.php?userid=107113](http://forums.novell.com/member.php?userid=107113)  
View this thread: [http://forums.novell.com/showthread.php?t=449083](http://forums.novell.com/showthread.php?t=449083)

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/flex022/uploads/suse/original/2X/5/5012ba89e3ffb5220dac47d5ea0ba032e2fe1cb6.png) [@system](https://forums.suse.com/u/system)
#### Post date: [December 4, 2011, 5:57pm UTC](https://forums.suse.com/t/ssh-failed-to-open-a-secure-file-transfer-session/21975/6 "2011-12-04T17:57:56Z")

</div>

On Sun, 04 Dec 2011 15:46:02 GMT  
hoiyi88 [hoiyi88@no-mx.forums.novell.com](mailto:hoiyi88@no-mx.forums.novell.com) wrote:

[CODE]  
www:~ # sftp -vv [root@127.0.0.1](mailto:root@127.0.0.1)  
Connecting to 127.0.0.1…  
OpenSSH\_5.1p1, OpenSSL 0.9.8a 11 Oct 2005  
…  
debug1: expecting SSH2\_MSG\_KEX\_DH\_GEX\_REPLY  
debug2: no key of type 0 for host 127.0.0.1  
debug2: no key of type 2 for host 127.0.0.1  
The authenticity of host ‘127.0.0.1 (127.0.0.1)’ can’t be established.

[CODE]  
Hi  
Is there an existing .ssh directory in /root?

I see in (SLES 11 SP1);

```auto
# sftp -vv root@127.0.0.1

Connecting to 127.0.0.1...
OpenSSH_5.1p1, OpenSSL 0.9.8h 28 May 2008
......
debug1: expecting SSH2_MSG_KEX_DH_GEX_REPLY
debug1: Host '127.0.0.1' is known and matches the RSA host key.
debug1: Found key in /root/.ssh/known_hosts:1
```

Your OpenSSL is at version a, SLE11 SP1 is at h, not sure if this may  
be causing an issue or the RSA keys.

–  
Cheers Malcolm Â°Â¿Â° (Linux Counter #276890)  
openSUSE 11.4 (x86\_64) Kernel 2.6.37.6-0.9-desktop  
up 3 days 16:52, 5 users, load average: 0.09, 0.08, 0.15  
GPU GeForce 8600 GTS Silent - Driver Version: 290.10

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/flex022/uploads/suse/original/2X/5/5012ba89e3ffb5220dac47d5ea0ba032e2fe1cb6.png) [@system](https://forums.suse.com/u/system)
#### Post date: [December 5, 2011, 9:06am UTC](https://forums.suse.com/t/ssh-failed-to-open-a-secure-file-transfer-session/21975/7 "2011-12-05T09:06:02Z")

</div>

malcolmlewis;2158428 Wrote:[color=blue]

> On Sun, 04 Dec 2011 15:46:02 GMT  
> hoiyi88 [hoiyi88@no-mx.forums.novell.com](mailto:hoiyi88@no-mx.forums.novell.com) wrote:[color=green]
> 
> > [/color][/color]  
> > Code:  
> > --------------------[color=blue][color=green]  
> > [/color]  
> > www:~ # sftp -vv [root@127.0.0.1](mailto:root@127.0.0.1)  
> > Connecting to 127.0.0.1…  
> > OpenSSH\_5.1p1, OpenSSL 0.9.8a 11 Oct 2005  
> > …  
> > debug1: expecting SSH2\_MSG\_KEX\_DH\_GEX\_REPLY  
> > debug2: no key of type 0 for host 127.0.0.1  
> > debug2: no key of type 2 for host 127.0.0.1  
> > The authenticity of host ‘127.0.0.1 (127.0.0.1)’ can’t be established.[color=green]  
> > [/color][/color]  
> > Code:  
> > --------------------[color=blue][color=green]  
> > [/color]  
> > Hi  
> > Is there an existing .ssh directory in /root?
> 
> I see in (SLES 11 SP1);[color=green]  
> \>[/color][/color]  
> Code:  
> --------------------[color=blue][color=green]  
> \>[/color]
> 
> # sftp -vv [root@127.0.0.1](mailto:root@127.0.0.1)
> 
> Connecting to 127.0.0.1…  
> OpenSSH\_5.1p1, OpenSSL 0.9.8h 28 May 2008  
> …  
> debug1: expecting SSH2\_MSG\_KEX\_DH\_GEX\_REPLY  
> debug1: Host ‘127.0.0.1’ is known and matches the RSA host key.  
> debug1: Found key in /root/.ssh/known\_hosts:1  
> [/color]  
> --------------------[color=blue][color=green]  
> \>[/color]  
> Your OpenSSL is at version a, SLE11 SP1 is at h, not sure if this may  
> be causing an issue or the RSA keys.
> 
> –  
> Cheers Malcolm Â°Â¿Â° (Linux Counter #276890)  
> openSUSE 11.4 (x86\_64) Kernel 2.6.37.6-0.9-desktop  
> up 3 days 16:52, 5 users, load average: 0.09, 0.08, 0.15  
> GPU GeForce 8600 GTS Silent - Driver Version: 290.10 \> \>
> 
> on /root/ have .ssh folder[/color]

## – hoiyi88

hoiyi88’s Profile: [http://forums.novell.com/member.php?userid=107113](http://forums.novell.com/member.php?userid=107113)  
View this thread: [http://forums.novell.com/showthread.php?t=449083](http://forums.novell.com/showthread.php?t=449083)

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/flex022/uploads/suse/original/2X/5/5012ba89e3ffb5220dac47d5ea0ba032e2fe1cb6.png) [@system](https://forums.suse.com/u/system)
#### Post date: [December 5, 2011, 9:46am UTC](https://forums.suse.com/t/ssh-failed-to-open-a-secure-file-transfer-session/21975/8 "2011-12-05T09:46:02Z")

</div>

malcolmlewis;2158428 Wrote:[color=blue]

> On Sun, 04 Dec 2011 15:46:02 GMT  
> hoiyi88 [hoiyi88@no-mx.forums.novell.com](mailto:hoiyi88@no-mx.forums.novell.com) wrote:[color=green]
> 
> > [/color][/color]  
> > Code:  
> > --------------------[color=blue][color=green]  
> > [/color]  
> > www:~ # sftp -vv [root@127.0.0.1](mailto:root@127.0.0.1)  
> > Connecting to 127.0.0.1…  
> > OpenSSH\_5.1p1, OpenSSL 0.9.8a 11 Oct 2005  
> > …  
> > debug1: expecting SSH2\_MSG\_KEX\_DH\_GEX\_REPLY  
> > debug2: no key of type 0 for host 127.0.0.1  
> > debug2: no key of type 2 for host 127.0.0.1  
> > The authenticity of host ‘127.0.0.1 (127.0.0.1)’ can’t be established.[color=green]  
> > [/color][/color]  
> > Code:  
> > --------------------[color=blue][color=green]  
> > [/color]  
> > Hi  
> > Is there an existing .ssh directory in /root?
> 
> I see in (SLES 11 SP1);[color=green]  
> \>[/color][/color]  
> Code:  
> --------------------[color=blue][color=green]  
> \>[/color]
> 
> # sftp -vv [root@127.0.0.1](mailto:root@127.0.0.1)
> 
> Connecting to 127.0.0.1…  
> OpenSSH\_5.1p1, OpenSSL 0.9.8h 28 May 2008  
> …  
> debug1: expecting SSH2\_MSG\_KEX\_DH\_GEX\_REPLY  
> debug1: Host ‘127.0.0.1’ is known and matches the RSA host key.  
> debug1: Found key in /root/.ssh/known\_hosts:1  
> [/color]  
> --------------------[color=blue][color=green]  
> \>[/color]  
> Your OpenSSL is at version a, SLE11 SP1 is at h, not sure if this may  
> be causing an issue or the RSA keys.
> 
> –  
> Cheers Malcolm Â°Â¿Â° (Linux Counter #276890)  
> openSUSE 11.4 (x86\_64) Kernel 2.6.37.6-0.9-desktop  
> up 3 days 16:52, 5 users, load average: 0.09, 0.08, 0.15  
> GPU GeForce 8600 GTS Silent - Driver Version: 290.10 \> \>
> 
> i found another version is OpenSSH\_5.1p1, OpenSSL 0.9.8a 11 Oct 2005.  
> but the SLES version same 10 SP4. can i downgrade?  
> Thanks[/color]

## – hoiyi88

hoiyi88’s Profile: [http://forums.novell.com/member.php?userid=107113](http://forums.novell.com/member.php?userid=107113)  
View this thread: [http://forums.novell.com/showthread.php?t=449083](http://forums.novell.com/showthread.php?t=449083)

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/flex022/uploads/suse/original/2X/5/5012ba89e3ffb5220dac47d5ea0ba032e2fe1cb6.png) [@system](https://forums.suse.com/u/system)
#### Post date: [December 5, 2011, 11:46am UTC](https://forums.suse.com/t/ssh-failed-to-open-a-secure-file-transfer-session/21975/9 "2011-12-05T11:46:02Z")

</div>

Change /etc/ssh/sshd\_config

Subsystem sftp /usr/lib64/ssh/sftp-server

successs

## – hoiyi88

hoiyi88’s Profile: [http://forums.novell.com/member.php?userid=107113](http://forums.novell.com/member.php?userid=107113)  
View this thread: [http://forums.novell.com/showthread.php?t=449083](http://forums.novell.com/showthread.php?t=449083)
