Re: Help request: problems with a 5.1 server and large numbers of ssh users.

From: Robert Watson (rwatson_at_freebsd.org)
Date: 11/20/03

  • Next message: Ken Smith: "Re: Help request: problems with a 5.1 server and large numbers of ssh users."
    Date: Thu, 20 Nov 2003 10:56:08 -0500 (EST)
    To: Len Sassaman <rabbi@anonymizer.com>
    
    

    On Wed, 19 Nov 2003, Len Sassaman wrote:

    > It is my intuition from this behavior that the sshd master process
    > listening for connections is unable to spawn a new process to complete
    > the authentication step, and thus the connection is being dropped. There
    > is no information of use in dmesg, nor in the system logs. (I've cranked
    > up LogLevel to DEBUG3 in sshd_config).
    >
    > I have a RedHat Linux server running the 2.4.18-3smp kernel on a dual
    > Athlon MP 1800+ and 2048MB RAM that is known to handle 1000 users
    > without issue -- so I have to believe the FreeBSD box, though not as
    > beefy hardware-wise, should be able to do better than a few hundred
    > users. I believe this to be some sort of resource limit issue, but I
    > have addressed everything I could think of.

    Hmm. Well, it certainly sounds like a resource limit to me, especially if
    it's a nice round number like "150" or "300". However, I'm also having a
    bit of trouble seeing, off the top of my head, which limit it might be.
    It sounds like you've got the ones I would think of. A quick skim of
    sshd.c suggests that it is pretty careful to document various failure
    modes in debugging output. There are one or two failures where it does
    not log, and they include the call to pipe() in the server loop -- if that
    fails, it bails without an error, which is a little surprising. Could you
    post server debug output for the first connection to the server that
    fails? This would let us "see how far it got"... In particular, whether
    it did spawn a child process, etc.

    Robert N M Watson FreeBSD Core Team, TrustedBSD Projects
    robert@fledge.watson.org Network Associates Laboratories

    _______________________________________________
    freebsd-hackers@freebsd.org mailing list
    http://lists.freebsd.org/mailman/listinfo/freebsd-hackers
    To unsubscribe, send any mail to "freebsd-hackers-unsubscribe@freebsd.org"


  • Next message: Ken Smith: "Re: Help request: problems with a 5.1 server and large numbers of ssh users."

    Relevant Pages

    • Re: Help request: problems with a 5.1 server and large numbers of ssh users.
      ... and thus the connection is being dropped. ... > I have a RedHat Linux server running the 2.4.18-3smp kernel on a dual ... I believe this to be some sort of resource limit issue, ... it did spawn a child process, ...
      (freebsd-current)
    • Re: Crossthread operation
      ... of the server I am creating. ... I spawn new threads for each connection that is created and would like to write the status to the console. ...
      (microsoft.public.dotnet.languages.csharp)
    • Crossthread operation
      ... I have a richtextbox that acts like a console with information on the status ... of the server I am creating. ... I spawn new threads for each connection that is ...
      (microsoft.public.dotnet.languages.csharp)
    • Re: Outgoing POP3 email missing/lost/not received
      ... Funny thing is that I have had this ISP for 8 years and it has always been ... It looks like when you last ran CEICW, you set the ISP's mail server to: ... Internet Connection Wizard. ... After the wizard completes, the following network connection ...
      (microsoft.public.windows.server.sbs)
    • Re: Cannot connect client to server 2003
      ... you need to reconfigure the IP schema of your SBS ... On the SBS 2003 Server open the Server Management console. ... On the Connection Type page, click Broadband, and then click Next. ... Alternate DNS server, type the IP addresses that are provided by your ISP ...
      (microsoft.public.windows.server.sbs)