This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Remote Log Server and SSH

Greetings Community,

 

Today I found a solution to a Problem that has occurred since 21 August 2026.

 

Problem:

Remote Log Server process stop transferring logs to an external log server.

Troubleshooting:

  1. Ran logarchiver.plx -d15 -t . Requires password.
  2. Generated new keys and placed them in the authorized_hosts and known_hosts files on the remote server.
  3. Ran logarchiver.plx -d15 -t . Requires password.
  4. Ran /usr/sbin/logrotate -v /etc/logrotate.conf. Requires password for every file that will be transferred.
  5. Tried scp and ssh from UTM9 to remote server, worked without a password.
  6. Checked the authorized_hosts and known_hosts. Both only had rsa key.
  7. Added dsa key to remote server authorized_hosts and known_hosts.
  8. Ran logarchiver.plx -d15 -t . Requires password.
  9. Checked the community couldn't find anyone with a similar problem.
  10. Checked the internet for OpenSSH, solution found.

Solution

According to the information on the internet in regards to OpenSSH

  1. dsa type is disabled as default
  2. The sshd_config file need to have an entry to allow dsa key type usage
    1. Added PubkeyAcceptedKeyTypes=+ssh-ds to the sshd_config file
    2. Tested using /usr/sbin/sshd -p 22 -d -f /etc/config/ssh/sshd_config  on the server and ssh -vvv -i .ssh/id_dsa admin@192.168.1.14 on the UTM9
    3. Test was successful, a password was not required and the connection was made.

 

It would be nice if this information was published somewhere on the Sophos website or in the support forum.

Also, why does the Sophos require the dsa key instead of the rsa key for the Remote Log Server transfer? According to the information on OpenSSH, dsa will eventually be discontinued in the future and is currently disabled since version 7 (Sophos 9.407-3 is currently using OpenSSH 6.2p2)

I hope this information is useful for others in the community.



This thread was automatically locked due to age.