SSH Slow Login even with SSHD UseDNS no parameter

I couldn't understand why on one system it took a few minutes to get the SSH login prompt when connecting to other systems. The other systems all had the UseDNS parameter set to no, which almost always resolves the login prompt delay.

The reason is Ubuntu and perhaps Debian and other distributions /etc/nsswitch.conf file

Edit yours to have the "hosts" line like so (notice that files and dns are the primary resolution choice)

hosts:          files dns mdns4_minimal [NOTFOUND=return] dns mdns4


If the above does not work - disable GSSAPI auth

This permanently caused my slow SSH login problems:

Edit vi /etc/ssh/ssh_config

Disable GSSAPI auth by setting the following line (make sure to uncomment or change the existing line if there is one that says yes):

GSSAPIAuthentication no

I realized what has happening by running -v with SSH, it kept timing out and trying to use GSSAPIAuthentication before trying password, unlike some older systems I have.

I'm sure this is a real annoyance for a lot of people too.


Tags:

ssh, login, sshd, usedns, parameteri, couldn, prompt, connecting, parameter, resolves, ubuntu, debian, distributions, etc, nsswitch, conf, edit, quot, hosts, dns, primary, resolution, mdns, _minimal, notfound, disable, gssapi, auth, permanently, vi, ssh_config, uncomment, existing, gssapiauthentication, password, annoyance,

Latest Articles

  • Proxmox How To Purge Ceph
  • VMWare ESXi/VSphere Disable Balloon Segfault in Services Solution
  • Apache Linux Debian Ubuntu Container how to manually restart without killing
  • Docker enable UTF8 in Container to stop seeing gibberish ? characters
  • Debian 8 How To Use Apt Update Archive sources.list
  • Debian Live CD Password
  • Forbidden You don't have permission to access this resource. [authz_core:error] [pid 338:tid 338] [client 1.2.3.4:55046] AH01630: client denied by server configuration:
  • The client needs a new connection for this request as the requested host name does not match the Server Name Indication (SNI) in use for this connection.
  • Asterisk RTP/audio not working in either direction in Docker NAT with a NAT client
  • dovecot: imap(root@localhost)<3702>: Error: Mailbox INBOX: mmap(size=352609044) failed with file /var/spool/mail/root/Maildir/dovecot.index.cache: Cannot allocate memory
  • Asterisk cannot find soundfile file.c:824 ast_openstream_full: File for-tech-support does not exist in any format
  • Apache Error solution - mktemp: failed to create directory via template '/var/lock/apache2.XXXXXXXXXX': No such file or directory
  • sysctl settings to reduce buffers and caches in Linux
  • Find /dev/sd block device of ata device - ata6: SATA link up 1.5 Gbps (SStatus 113 SControl 310) ata6.00: qc timeout (cmd 0xec) ata6.00: failed to IDENTIFY (I/O error, err_mask=0x4) ata6.00: revalidation failed (errno=-5)
  • Stuttering Audio on VOIP phones when first answering a call slow and fast audio
  • How to distribute the Microsoft VC Visual Studio Redistributable Files On Your Own
  • Nvidia video resolution and codec encode decode support matrix eg. h264 4k h265 HEVC VP9 Card List from GTX, RTX, Quadro
  • Japan and China ping time observations
  • ffmpeg convert to another format eg h265 to h264
  • Apache stop bots and hackers by using forensic logging.