Collecting cluster report fails while required to use forwarded SSH agent

This document (000020662) is provided subject to the disclaimer at the end of this document.

Environment

SUSE Linux Enterprise Server 15 SP3
SUSE Linux Enterprise Server for SAP Applications 15 SP3

Situation

Due to a restricted environment requirements sysadmins are required to do only SSH 'publickey' authentication method (ie. password interactive login is forbidden); forwarded SSH agent is also used when attempting to collect cluster report (eg. no SSH private keys are allowed to be located on the cluster nodes).


A sysadmin is using SSH agent and collection of cluster report fails

A sysadmin needs to collect cluster report from two nodes, he uses SSH agent forwarding as loading SSH private keys onto the systems is forbidden; the sysadmin expects SSH connection from one node to the other would use his SSH forwarded via SSH agent.

First see that public key authentication proxied via SSH agent works as expected:
# s153cl1 - main node
sadmin1@s153cl1:~> echo $SSH_AUTH_SOCK
/tmp/ssh-rDTCYLyHvd/agent.2865

# checking other node from main node
sadmin1@s153cl1:~> ssh -v s153cl2 hostname 2>&1 | \
    grep -P '(Server accepts key:|^s153)'
debug1: Server accepts key: sadmin1@workstation RSA SHA256:KMxvvfn9io9D1y/QY0tnJ4AxYKziX3F3G0oCrP3fFDA agent
s153cl2

Now see that sudo rules as added on both nodes:
$ sudo -l | tail -n1
    (root) NOPASSWD: /usr/sbin/crm report *

Finally, the attempt to collect cluster report while using SSH agent, it fails:
sadmin1@s153cl1:~> sudo /usr/sbin/crm report -v -u sadmin1
INFO: s153cl1# setting PCMK_LIB to /var/lib/pacemaker
INFO: s153cl1# log settings: facility=daemon logfile=None debugfile=None
INFO: s153cl1# nodes: s153cl2 s153cl1
INFO: s153cl1# ssh sadmin1@s153cl2 failed
WARNING: s153cl1# passwordless ssh to node(s)  s153cl2 does not work
INFO: s153cl1# ssh user other than root, use sudo
INFO: s153cl1# journalctl from: '1654048920' until: '0' from_time: '2022-06-01 04:02' to_time: '2022-06-01 16:02' > /tmp/.hb_report.workdir.2kVGBh/hb_report-Wed-01-Jun-2022/journal.log
INFO: s153cl1# the log file is in the rfc5424 format
INFO: s153cl1# found log /var/log/messages
INFO: s153cl1# the log file is in the rfc5424 format
INFO: s153cl1# Including segment [1-27288] from /var/log/messages
INFO: s153cl1# Please provide password for sadmin1 at s153cl2
INFO: s153cl1# Note that collecting data will take a while.
WARNING: s153cl1# sadmin1@s153cl2: Permission denied (publickey).
INFO: s153cl1# Trying connect by 192.168.122.12
WARNING: s153cl1# sadmin1@192.168.122.12: Permission denied (publickey).

Traceback (most recent call last):
  File "/usr/share/crmsh/hb_report/hb_report", line 423, in <module>
    run()
  File "/usr/share/crmsh/hb_report/hb_report", line 282, in run
    collect_for_nodes(constants.NODES, arg_str)
  File "/usr/share/crmsh/hb_report/hb_report", line 27, in collect_for_nodes
    utillib.start_slave_collector(node, arg_str)
  File "/usr/share/crmsh/hb_report/utillib.py", line 1551, in start_slave_collector
    crmutils.get_stdout(cmd, input_s=eval(compress_data))
  File "<string>", line 0
    
    ^
SyntaxError: unexpected EOF while parsing
INFO: s153cl1# remove tempfile "/tmp/tmp.5ylypr9pBXn5"

 

Resolution

A sysadmin is using SSH agent and collection of cluster report fails


The failure is reported to engineering. Currently, one can collect cluster report from single nodes, one by one.
ssh <user>@<cluster node> sudo -u root /usr/sbin/crm report -S /home/<user>/<cluster node>

And then download the cluster report archive from the nodes from /home/<user>/<cluster node>.tar.bz2.

Cause

A sysadmin is using SSH agent and collection of cluster report fails


Currently, the code does not work correctly with SSH agent, engineering is informed about the issue.

Status

Reported to Engineering

Additional Information

  • https://documentation.suse.com/sle-ha/15-SP3/html/SLE-HA-all/app-crmreport-nonroot.html

Disclaimer

This Support Knowledgebase provides a valuable tool for SUSE customers and parties interested in our products and solutions to acquire information, ideas and learn from one another. Materials are provided for informational, personal or non-commercial use within your organization and are presented "AS IS" WITHOUT WARRANTY OF ANY KIND.

  • Document ID:000020662
  • Creation Date: 30-May-2022
  • Modified Date:01-Jun-2022
    • SUSE Linux Enterprise High Availability Extension
    • SUSE Linux Enterprise Server for SAP Applications

< Back to Support Search

For questions or concerns with the SUSE Knowledgebase please contact: tidfeedback@suse.com

SUSE Support Forums

Get your questions answered by experienced Sys Ops or interact with other SUSE community experts.

Join Our Community

Support Resources

Learn how to get the most from the technical support you receive with your SUSE Subscription, Premium Support, Academic Program, or Partner Program.


SUSE Customer Support Quick Reference Guide SUSE Technical Support Handbook Update Advisories
Support FAQ

Open an Incident

Open an incident with SUSE Technical Support, manage your subscriptions, download patches, or manage user access.

Go to Customer Center