Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17

x
?
Solved

What port does X11 Forwarding with SSH use?

Posted on 2013-01-17
16
Medium Priority
?
3,142 Views
Last Modified: 2013-02-14
I'm using Putty and Xming on Windows to connect to an AIX box.  I'm connecting via SSH, but when I launch an application, it always comes back to the Windows box on port 6000.

I know 6000 is default for X11, but I thought the app would come to the Windows system on port 22 since it's using SSH.

Please advise.  I'm working hard to understand this.
0
Comment
Question by:fuze44
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 8
  • 6
  • 2
16 Comments
 
LVL 40

Assisted Solution

by:omarfarid
omarfarid earned 300 total points
ID: 38790362
It looks like that your X11 S/W and ssh are not configured properly on the windows side.

Check your putty and Xming config for X11 tunneling / forwarding.
0
 
LVL 68

Expert Comment

by:woolmilkporc
ID: 38792037
Make sure that PuTTY's X11 forwarding is enabled.

Configuration -> SSH -> X11 -> tick "Enable X11 forwarding". Leave "X display location" empty.

Make sure that all settings are saved in the session profile.

Once you're logged in to your target host, check the DISPLAY variable.

It should be: "localhost:10.0"

Never ever set the DISPLAY variable to something else (e. g. to the address of your Windows machine, as you would do without SSH tunneling).
0
 

Author Comment

by:fuze44
ID: 38795191
I have done all of that, but when $DISPLAY shows to be localhost:10.0 no windows will open.  

Xming (the Windows X Server) is using display 0.  Should it be changed to 10?
0
Migrating Your Company's PCs

To keep pace with competitors, businesses must keep employees productive, and that means providing them with the latest technology. This document provides the tips and tricks you need to help you migrate an outdated PC fleet to new desktops, laptops, and tablets.

 
LVL 68

Accepted Solution

by:
woolmilkporc earned 1200 total points
ID: 38797150
No,

localhost:10.0 is quite correct with Xming display 0:0.

This display is intercepted by the ssh daemon on the remote AIX machine, tunneled through ssh then forwarded to yout local display :0.0.

So if your Xming display is indeed :0.0 everything should work fine. If your Xming display were e.g. :0.1, however, then enter this as "localhost:0.1" at "X display location" in the PuTTY setup (the field you initially left empty).

If you didn't see any error message when starting e. g. "xclock" on AIX then this window must appear somewhere on Windows. Did you choose "Multiple Window" mode of Xming? Otherwise the xclock display will appear in the Xming main window.

Which X application are you using on AIX? Could it be that this application has its own setup mechanism containing a DISPLAY setting which overrrides the original "localhost:10.0" value?
0
 

Author Comment

by:fuze44
ID: 38797383
The X app is an old software engineering app from which I'm migrating the data to a new app.  I can get its windows to appear using just X11 without SSH by setting DISPLAY to my workstation's address via a Telnet session.  When I connect via SSH, I get an error about not being able to open the window.

It will be Tuesday before I can get back on that system at work.   I'll get more details then and double check all of these settings.
0
 
LVL 68

Expert Comment

by:woolmilkporc
ID: 38797389
"... not being able to open the _window_ " or rather "... to open the _display_"?
0
 

Author Comment

by:fuze44
ID: 38821158
Ok, I've been trying hard to get this to work.  BTW, this is OpenSSH that has been installed onto the AIX server.  Here's where things stand:

I can still bring up X Windows using telnet and setting my display to my local IP.  I then try it via SSH in Putty,  with X11 forwarding checked.  I leave the remote DISPLAY set to localhost:10.0, but when I try to start nedit or xterm, I get:

Xlib:  connection to "localhost:10.0" refused by server
Xlib:  PuTTY X11 proxy: wrong authentication protocol attempted
Error: Can't open display: localhost:10.0

I've edited my sshd_config file to have the following values:

AllowTcpForwarding yes
X11Forwarding yes
X11DisplayOffset 10
X11UseLocalhost yes
XAuthLocation /usr/bin/X11/xauth

I've removed and regenerated the .Xauthority file.  I've restarted the ssh daemon.

I'm stuck.
0
 

Author Comment

by:fuze44
ID: 38821194
Also, here's the log from Putty:

2013-01-25 20:20:42      Looking up host "162.58.43.95"
2013-01-25 20:20:42      Connecting to 162.58.43.95 port 22
2013-01-25 20:20:42      Server version: SSH-2.0-OpenSSH_5.8
2013-01-25 20:20:42      We claim version: SSH-2.0-PuTTY_Release_0.60
2013-01-25 20:20:42      Using SSH protocol version 2
2013-01-25 20:20:42      Doing Diffie-Hellman group exchange
2013-01-25 20:20:42      Doing Diffie-Hellman key exchange with hash SHA-256
2013-01-25 20:20:45      Host key fingerprint is:
2013-01-25 20:20:45      ssh-rsa 2048 58:55:a8:1d:4e:f9:fc:82:6e:90:44:cc:36:fb:65:61
2013-01-25 20:20:45      Initialised AES-256 SDCTR client->server encryption
2013-01-25 20:20:45      Initialised HMAC-SHA1 client->server MAC algorithm
2013-01-25 20:20:45      Initialised AES-256 SDCTR server->client encryption
2013-01-25 20:20:45      Initialised HMAC-SHA1 server->client MAC algorithm
2013-01-25 20:20:46      Keyboard-interactive authentication refused
2013-01-25 20:20:48      Sent password
2013-01-25 20:20:48      Access granted
2013-01-25 20:20:48      Opened channel for session
2013-01-25 20:20:48      Requesting X11 forwarding
2013-01-25 20:20:48      X11 forwarding enabled
2013-01-25 20:20:48      Allocated pty (ospeed 38400bps, ispeed 38400bps)
2013-01-25 20:20:48      Started a shell/command

>> Right here I entered 'nedit'

2013-01-25 20:21:59      Received X11 connect request from 127.0.0.1:4242
2013-01-25 20:21:59      Opening X11 forward connection succeeded
2013-01-25 20:21:59      Forwarded X11 connection terminated
0
 
LVL 40

Expert Comment

by:omarfarid
ID: 38821768
try to run the command

xhost +

before running nedit
0
 
LVL 68

Expert Comment

by:woolmilkporc
ID: 38821882
Use MIT-Magic-Cookie-1 instead of XDM-Authorization-1 in PuTTY's session configuration.
0
 

Author Comment

by:fuze44
ID: 38836899
I am using Magic Cookies (although my log posted above may have indicated differently since I tried both).

As for xhost +, it just generates the same error as when I'm trying to run an app like nedit:

root(waas-tw)> xhost +
Xlib:  connection to "localhost:10.0" refused by server
Xlib:  PuTTY X11 proxy: wrong authentication protocol attempted
1356-200 xhost unable to open display "localhost:10.0"
0
 
LVL 68

Expert Comment

by:woolmilkporc
ID: 38836965
Run "xhost +" on Xming, not on AIX.
0
 

Author Comment

by:fuze44
ID: 38837857
What do you mean run that on Xming?  There's no Xmine command line that I know of, nor is there a program called xhost installed with Xming, so that isn't recognize from Window's command line.

There is an -ac option which allows all clients.  That is in place.  There is also the X0.hosts file for specific hosts.  The remote machines is listed in there.
0
 
LVL 68

Assisted Solution

by:woolmilkporc
woolmilkporc earned 1200 total points
ID: 38839015
Could it be that the home directory of the user in question resides on an NFS share?

I saw this problem in the past even when the share had full write access by everybody (including root).

For some obscure reason ssh cannot update the user's .Xauthority file when it's on NFS (but not with all users, to make it really mysterious).
.
Could you check the modification date of that file (if it does exist at all)? Does it reflect the last time you logged in via ssh + X11 forwarding, or is it old?

Could you try logging in as a user whose home directory is not on NFS? Maybe "root"?
0
 

Author Comment

by:fuze44
ID: 38890887
Ok, I got it working.  Every webpage I found said to set X11UseLocalhost to yes in sshd_config.  Turns out that 'no' is the correct setting for this configuration.

My cohorts behind the firewall can now receive X windows.
0
 

Author Closing Comment

by:fuze44
ID: 38890904
Since the solution was something else, I awarded points for participation and information.  Thank you, all.
0

Featured Post

Does Your Cloud Backup Use Blockchain Technology?

Blockchain technology has already revolutionized finance thanks to Bitcoin. Now it's disrupting other areas, including the realm of data protection. Learn how blockchain is now being used to authenticate backup files and keep them safe from hackers.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Note: for this to work properly you need to use a Cross-Over network cable. 1. Connect both servers S1 and S2 on the second network slots respectively. Note that you can use the 1st slots but usually these would be occupied by the Service Provide…
Fine Tune your automatic Updates for Ubuntu / Debian
Learn how to navigate the file tree with the shell. Use pwd to print the current working directory: Use ls to list a directory's contents: Use cd to change to a new directory: Use wildcards instead of typing out long directory names: Use ../ to move…
Connecting to an Amazon Linux EC2 Instance from Windows Using PuTTY.
Suggested Courses

721 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question