The Community Forums

Interact with an entire community of cPanel & WHM users!
  1. This site uses cookies. By continuing to use this site, you are agreeing to our use of cookies. Learn More.

cannot ssh into server sshd is up per status everything else works fine too

Discussion in 'General Discussion' started by Phylum, Dec 27, 2012.

  1. Phylum

    Phylum Active Member

    Joined:
    Apr 20, 2010
    Messages:
    29
    Likes Received:
    0
    Trophy Points:
    1
    Although sshd is running, the moment a client it seems to fail to auth and immediately disconnects. It disconnects before one can enter in a user or password or before it even reads the key. It does not return an incorrect/unknown user or pass error - it just quits. All other services are working fine: apache, mysql, bind, mysql, imap, smtp etc.

    Putty will return:
    PuTTY Fatal Error Network error: Software caused connection abort​

    Standard Linux ssh will return:
    Read from socket failed: Connection reset by peer

    I've performed the following
    • restarted ssh via whm
    • bounced the server when restarting the service didn't fix the problem
    • checked .ssh/authorized_keys to ensure they looked legit
    • replaced sshd_config with a known working copy (another instance where sshd is responding normally)
    • verified my pem/ppk files are ok
    • tried via root and other users
    • tried from multiple computers (windows, mac, Linux, Android )
    • tried from computers outside of my home network (the office, aws, mobile network)
    • tried from another vm within aws (another VM on the same subnet)
    • didn't notice anything crazy in tcpdump while trying to connect via ssh
    • checked iptables & flushed everything
    • disabled lfd, & brute force protection
    • no other firewalls enabled
    • verified aws security groups are properly setup
    • tried adding 'ListenAddress 0.0.0.0' to sshd_config
    • checked hosts.allow & hosts.deny
    • user present in shadow

    Its a virtual box not hosted on-site. I have no remote access (ssh, scp or telnet) to this machine. The only way I can 'get in' to retrieve logs or make configuration changes is to power it down, disconnect the volume, spin up another VM, attach & mount the volume. Once I grab what I need & make my changes changes, I reverse the process & power it back on. Again, after powering the box, it comes up fine & all services start (apache, mysql, imap, smtp, pop3, named, sshd etc) but ssh connection continue to fail.

    This is a CentOS 5.8 vm - installed about 2 weeks ago. yum update'd before & after installing cpanel. Was working fine up until Dec 24th; I disconnected when the FiOS guy came to install the new service. Haven't been able to reconnect since.
    The last couple of changes that I can think of was editing /etc/hosts but I don't see how that would break it.

    More logs here
    http://pastebin.com/DG9ids8G
    http://pastebin.com/VDjQqEDP
    http://pastebin.com/eL3mdTnW

    Some Sample output
    Code:
    $ ssh -vvvo PreferredAuthentications=password user@10.0.0.22
    OpenSSH_5.3p1, OpenSSL 1.0.0j-fips 10 May 2012
    debug1: Reading configuration data /etc/ssh/ssh_config
    debug1: Applying options for *
    debug2: ssh_connect: needpriv 0
    debug1: Connecting to 10.0.0.22 [10.0.0.22] port 22.
    debug1: Connection established.
    debug1: identity file /home/ec2-user/.ssh/identity type -1
    debug1: identity file /home/ec2-user/.ssh/id_rsa type -1
    debug1: identity file /home/ec2-user/.ssh/id_dsa type -1
    debug1: Remote protocol version 2.0, remote software version OpenSSH_4.3
    debug1: match: OpenSSH_4.3 pat OpenSSH_4*
    debug1: Enabling compatibility mode for protocol 2.0
    debug1: Local version string SSH-2.0-OpenSSH_5.3
    debug2: fd 3 setting O_NONBLOCK
    debug1: SSH2_MSG_KEXINIT sent
    debug3: Wrote 792 bytes for a total of 813
    Connection closed by UNKNOWN
    
    $ ssh -vvvo PreferredAuthentications=password user@10.0.0.22 -F /dev/null
    OpenSSH_5.3p1, OpenSSL 1.0.0j-fips 10 May 2012
    debug1: Reading configuration data /dev/null
    debug2: ssh_connect: needpriv 0
    debug1: Connecting to 10.0.0.22 [10.0.0.22] port 22.
    debug1: Connection established.
    debug1: identity file /home/ec2-user/.ssh/identity type -1
    debug1: identity file /home/ec2-user/.ssh/id_rsa type -1
    debug1: identity file /home/ec2-user/.ssh/id_dsa type -1
    debug1: Remote protocol version 2.0, remote software version OpenSSH_4.3
    debug1: match: OpenSSH_4.3 pat OpenSSH_4*
    debug1: Enabling compatibility mode for protocol 2.0
    debug1: Local version string SSH-2.0-OpenSSH_5.3
    debug2: fd 3 setting O_NONBLOCK
    debug1: SSH2_MSG_KEXINIT sent
    debug3: Wrote 792 bytes for a total of 813
    Connection closed by UNKNOWN
    
    $ ssh -vvvo PreferredAuthentications=password -c aes256-ctr user@10.0.0.22
    OpenSSH_5.3p1, OpenSSL 1.0.0j-fips 10 May 2012
    debug1: Reading configuration data /etc/ssh/ssh_config
    debug1: Applying options for *
    debug2: ssh_connect: needpriv 0
    debug1: Connecting to 10.0.0.22 [10.0.0.22] port 22.
    debug1: Connection established.
    debug1: identity file /home/ec2-user/.ssh/identity type -1
    debug1: identity file /home/ec2-user/.ssh/id_rsa type -1
    debug1: identity file /home/ec2-user/.ssh/id_dsa type -1
    debug1: Remote protocol version 2.0, remote software version OpenSSH_4.3
    debug1: match: OpenSSH_4.3 pat OpenSSH_4*
    debug1: Enabling compatibility mode for protocol 2.0
    debug1: Local version string SSH-2.0-OpenSSH_5.3
    debug2: fd 3 setting O_NONBLOCK
    debug1: SSH2_MSG_KEXINIT sent
    debug3: Wrote 496 bytes for a total of 517
    Read from socket failed: Connection reset by peer
    
    $ ssh -vvvo PreferredAuthentications=password -c aes256-ctr user@10.0.0.22 -F /dev/null
    OpenSSH_5.3p1, OpenSSL 1.0.0j-fips 10 May 2012
    debug1: Reading configuration data /dev/null
    debug2: ssh_connect: needpriv 0
    debug1: Connecting to 10.0.0.22 [10.0.0.22] port 22.
    debug1: Connection established.
    debug1: identity file /home/ec2-user/.ssh/identity type -1
    debug1: identity file /home/ec2-user/.ssh/id_rsa type -1
    debug1: identity file /home/ec2-user/.ssh/id_dsa type -1
    debug1: Remote protocol version 2.0, remote software version OpenSSH_4.3
    debug1: match: OpenSSH_4.3 pat OpenSSH_4*
    debug1: Enabling compatibility mode for protocol 2.0
    debug1: Local version string SSH-2.0-OpenSSH_5.3
    debug2: fd 3 setting O_NONBLOCK
    debug1: SSH2_MSG_KEXINIT sent
    debug3: Wrote 496 bytes for a total of 517
    Connection closed by UNKNOWN
     
    #1 Phylum, Dec 27, 2012
    Last edited: Dec 27, 2012
  2. cPanelMichael

    cPanelMichael Forums Analyst
    Staff Member

    Joined:
    Apr 11, 2011
    Messages:
    30,854
    Likes Received:
    676
    Trophy Points:
    113
    cPanel Access Level:
    Root Administrator
    Re: cannot ssh into server sshd is up per status everything else works fine

    Hello :)

    You can try starting a temporary instance of SSH using the SSH Autofixer via Web Host Manager:

    Code:
    https://example.com:2087/scripts2/doautofixer?autofix=safesshrestart
    This should start SSH using default settings to help rule out your SSH configuration as the cause of the problem.

    Thank you.
     
  3. Phylum

    Phylum Active Member

    Joined:
    Apr 20, 2010
    Messages:
    29
    Likes Received:
    0
    Trophy Points:
    1
    Re: cannot ssh into server sshd is up per status everything else works fine

    Thanks for taking the time to review & reply!
    I also greatly appreciate that tip. While it did seem to complete successfully I continue to get the same errors when trying to connect.

    Code:
    AutoFixer Execution
    
    Requesting script ...
    
    Done.
    
    
    Executing script ...
    
    
    Attempting to locate sshd binaries installed on the system ...
    
    Located /usr/sbin/sshd
    
    Done.
    
    Killing exisiting sshd processes...
    
    Stopping sshd: [  OK  ]
    
    
    killed 17644 killed 17645 Done.
    
    configuring sshd to run on port 22
    
    /usr/sbin/sshd successfully started!
    
    root     18292  0.0  0.0  62700  1176 ?        Rs   09:05   0:00 /usr/sbin/sshd -f /var/cpanel/safe_sshd
    
    
    
    Done.
     
  4. cPanelMichael

    cPanelMichael Forums Analyst
    Staff Member

    Joined:
    Apr 11, 2011
    Messages:
    30,854
    Likes Received:
    676
    Trophy Points:
    113
    cPanel Access Level:
    Root Administrator
    Re: cannot ssh into server sshd is up per status everything else works fine

    In that case, you may want to consult with the data center where this server is hosted, or with the support for the virtualization software you are using.

    Thank you.
     
  5. Phylum

    Phylum Active Member

    Joined:
    Apr 20, 2010
    Messages:
    29
    Likes Received:
    0
    Trophy Points:
    1
    Re: cannot ssh into server sshd is up per status everything else works fine

    Thanks again. I am or rather have. I opened a ticket but they (Amazon) currently see it as a software or configuration issue, not related to their network config, infrastructure or hypervisor. They're still seemingly interested in helping me resolve this but I realize they technically don't have to. They, and others, have suggested I check with cPanel since it makes extensive modifications to the system.

    For what is worth, I've posted on the Amazon forums, CentOS 5 forums, here and even emailed the OpenSSH mailing list. Since I'm not sure where the problem lies, I'm reaching out for advice on what to look for/how to troubleshoot etc.
     
  6. JordanSmith

    JordanSmith Member

    Joined:
    Dec 28, 2012
    Messages:
    5
    Likes Received:
    0
    Trophy Points:
    1
    cPanel Access Level:
    Root Administrator
    Just had a thought, could it be Fios that could be blocking port 22, when I work from work I can't get through on port 22 but I can at home. Try on a different ISP and see if that solves your problem.
     
  7. Phylum

    Phylum Active Member

    Joined:
    Apr 20, 2010
    Messages:
    29
    Likes Received:
    0
    Trophy Points:
    1
    Re: cannot ssh into server sshd is up per status everything else works fine

    JordanSmith - thanks for taking a time to look into this.

    I'm under the impression that they (Verizon) are blocking only a handful of ports like http/s, imap, pop, smtp to help prevent spammers and discourage users from hosting websites etc. I don't have a list of those ports with me right now.

    However, all that's moot because I cannot ssh into the machine from 2 other non-FiOS/Verizon Internet connections. (8th bullet point) And from all three connections (my FiOS plus the other external connections) I can ssh into other machines. Its unique to this VM.
     
  8. txspaderz

    txspaderz Active Member
    PartnerNOC

    Joined:
    Jun 4, 2008
    Messages:
    38
    Likes Received:
    0
    Trophy Points:
    6
    Location:
    Houston
    cPanel Access Level:
    DataCenter Provider
    Re: cannot ssh into server sshd is up per status everything else works fine

    Could this be a dirty .bashrc file on either end?
     
  9. Phylum

    Phylum Active Member

    Joined:
    Apr 20, 2010
    Messages:
    29
    Likes Received:
    0
    Trophy Points:
    1
    Re: cannot ssh into server sshd is up per status everything else works fine

    txpaderz - Hi & thanks for replying!

    Plan of action for o'dark thirty tomorrow morning since I can't take it down during the day:
    check .bashrc files (thanks for the suggestion)
    uninstall/reinstall ssh: chroot then yum erase openssh-server && yum -y install openssh-server

    I did manage to create a cron job earlier this morning to run a script & email me the results - finally had some time to review it: ssh debugging - Pastebin.com

    Some things worth high lighting:
    Code:
    ## /var/log/messages
    ...
    Dec 28 09:05:53 daniel sshd[18292]: Server listening on 0.0.0.0 port 22.
    Dec 28 09:06:05 daniel kernel: [8101586.123735] sshd[18337]: segfault at 00005555c6a838a0 rip 00005555c6a838a0 rsp 00007fffe7021408 error 14
    Dec 28 10:04:19 daniel kernel: [8105080.190032] sshd[26161]: segfault at 00005554fd2418a0 rip 00005554fd2418a0 rsp 00007fffb0861c48 error 14
    Dec 28 10:05:51 daniel kernel: [8105171.946037] sshd[26176]: segfault at 000055557c5568a0 rip 000055557c5568a0 rsp 00007fff3154f1e8 error 14
    Dec 28 11:56:24 daniel kernel: [8111805.096347] sshd[3013]: segfault at 00005554d596d8a0 rip 00005554d596d8a0 rsp 00007fffd8135dc8 error 14
    Dec 28 11:57:50 daniel sshd[10747]: Did not receive identification string from 119.18.144.31
    Dec 28 12:05:32 daniel kernel: [8112353.069199] sshd[11574]: segfault at 00005555cf2378a0 rip 00005555cf2378a0 rsp 00007fffde86c508 error 14
    Dec 28 12:05:43 daniel kernel: [8112364.144714] sshd[12164]: segfault at 00005554dadf38a0 rip 00005554dadf38a0 rsp 00007fffd2cb0098 error 14
    Dec 28 12:05:45 daniel kernel: [8112365.967406] sshd[12167]: segfault at 000055551db278a0 rip 000055551db278a0 rsp 00007fff8ff7e368 error 14
    Dec 28 12:05:46 daniel kernel: [8112367.542307] sshd[12170]: segfault at 000055556a77b8a0 rip 000055556a77b8a0 rsp 00007fff43329708 error 14
    #EOF
    
    # I was connecting from another machine on the same subnet
    ## `sshd -dddDp 19999` results
    Server listening on 0.0.0.0 port 19999.
    debug3: fd 4 is not O_NONBLOCK
    debug1: Server will not fork when running in debugging mode.
    debug3: send_rexec_state: entering fd = 7 config len 619
    debug3: ssh_msg_send: type 0
    debug3: send_rexec_state: done
    debug1: rexec start in 4 out 4 newsock 4 pipe -1 sock 7
    debug1: inetd sockets after dupping: 3, 3
    Connection from 10.0.0.74 port 37821
    debug2: load_server_config: filename /etc/ssh/sshd_config
    debug2: load_server_config: done config len = 619
    debug2: parse_server_config: config /etc/ssh/sshd_config len 619
    debug1: sshd version OpenSSH_4.3p2
    debug3: Not a RSA1 key file /etc/ssh/ssh_host_rsa_key.
    debug1: read PEM private key done: type RSA
    debug1: private host key: #0 type 1 RSA
    debug3: Not a RSA1 key file /etc/ssh/ssh_host_dsa_key.
    debug1: read PEM private key done: type DSA
    debug1: private host key: #1 type 2 DSA
    debug1: rexec_argv[0]='/usr/sbin/sshd'
    debug1: rexec_argv[1]='-dddDp'
    debug1: rexec_argv[2]='19999'
    debug2: fd 3 setting O_NONBLOCK
    debug1: Bind to port 19999 on 0.0.0.0.
    Server listening on 0.0.0.0 port 19999.
    debug3: fd 4 is not O_NONBLOCK
    debug1: Server will not fork when running in debugging mode.
    debug3: send_rexec_state: entering fd = 7 config len 619
    debug3: ssh_msg_send: type 0
    debug3: send_rexec_state: done
    debug1: rexec start in 4 out 4 newsock 4 pipe -1 sock 7
    debug1: inetd sockets after dupping: 3, 3
    Connection from 10.0.0.74 port 37823
    #EOF
     
    ## /var/log/secure
    Dec 28 07:19:27 daniel sshd[2096]: debug2: fd 3 setting O_NONBLOCK
    Dec 28 07:19:27 daniel sshd[2096]: debug1: Bind to port 22 on 0.0.0.0.
    Dec 28 07:19:27 daniel sshd[2096]: Server listening on 0.0.0.0 port 22.
    Dec 28 08:14:50 daniel sshd[2096]: debug3: fd 4 is not O_NONBLOCK
    Dec 28 08:14:50 daniel sshd[10962]: debug1: rexec start in 4 out 4 newsock 4 pipe 6 sock 7
    Dec 28 08:14:50 daniel sshd[2096]: debug1: Forked child 10962.
    Dec 28 08:14:50 daniel sshd[2096]: debug3: send_rexec_state: entering fd = 7 config len 619
    Dec 28 08:14:50 daniel sshd[2096]: debug3: ssh_msg_send: type 0
    Dec 28 08:14:50 daniel sshd[2096]: debug3: send_rexec_state: done
    Dec 28 08:14:50 daniel sshd[10962]: debug1: inetd sockets after dupping: 3, 3
    Dec 28 08:14:50 daniel sshd[10962]: Connection from my.ip.add.ress port 21561
    Dec 28 09:05:53 daniel sshd[2096]: Received signal 15; terminating.
     
  10. Phylum

    Phylum Active Member

    Joined:
    Apr 20, 2010
    Messages:
    29
    Likes Received:
    0
    Trophy Points:
    1
    Re: cannot ssh into server sshd is up per status everything else works fine

    Ok so the situation is that sshd is segfaulting the moment a user connects. This is on a CentOS 5.6 x86_64 machine running OpenSSH 4.3p2-82.el5.

    Its core dumping but I don't know what I should do next.

    Code:
    # /usr/sbin/sshd -dddDp 19999
    debug2: load_server_config: filename /etc/ssh/sshd_config
    debug2: load_server_config: done config len = 526
    debug2: parse_server_config: config /etc/ssh/sshd_config len 526
    debug1: sshd version OpenSSH_4.3p2
    debug3: Not a RSA1 key file /etc/ssh/ssh_host_rsa_key.
    debug1: read PEM private key done: type RSA
    debug1: private host key: #0 type 1 RSA
    debug3: Not a RSA1 key file /etc/ssh/ssh_host_dsa_key.
    debug1: read PEM private key done: type DSA
    debug1: private host key: #1 type 2 DSA
    debug1: rexec_argv[0]='/usr/sbin/sshd'
    debug1: rexec_argv[1]='-dddDp'
    debug1: rexec_argv[2]='19999'
    debug2: fd 3 setting O_NONBLOCK
    debug1: Bind to port 19999 on 0.0.0.0.
    Server listening on 0.0.0.0 port 19999.
    socket: Address family not supported by protocol
    debug3: fd 4 is not O_NONBLOCK
    debug1: Server will not fork when running in debugging mode.
    debug3: send_rexec_state: entering fd = 7 config len 526
    debug3: ssh_msg_send: type 0
    debug3: send_rexec_state: done
    debug1: rexec start in 4 out 4 newsock 4 pipe -1 sock 7
    debug1: inetd sockets after dupping: 3, 3
    Connection from 127.0.0.1 port 41783
    Segmentation fault (core dumped)
     
    ==> /var/log/messages <==
    Dec 29 03:57:30 daniel kernel: [4386322.743762] sshd[11068]: segfault at 00005554de2e38a0 rip 00005554de2e38a0 rsp 00007fffcf7c1f08 error 14
     
    #10 Phylum, Dec 29, 2012
    Last edited: Dec 29, 2012
  11. Phylum

    Phylum Active Member

    Joined:
    Apr 20, 2010
    Messages:
    29
    Likes Received:
    0
    Trophy Points:
    1
    Re: cannot ssh into server sshd is up per status everything else works fine

    I'm not even going to pretend I know what I'm doing or talking about here. By doing a bit of research (a fancy way of saying I 'Googled it') I was able to get this far but its not looking very useful/promising.

    So after installing debug symbols..

    core of /usr/sbin/sshd -dddDp 19999 in debug mode
    ### core of /usr/sbin/sshd -dddDp 19999
    Code:
    # gdb /usr/sbin/sshd /tmp/core/core-sshd-11-0-0-1347-1356793916
    GNU gdb (GDB) CentOS (7.0.1-42.el5.centos.1)
    Copyright (C) 2009 Free Software Foundation, Inc.
    License GPLv3+: GNU GPL version 3 or later <http://gnu.org/licenses/gpl.html>
    This is free software: you are free to change and redistribute it.
    There is NO WARRANTY, to the extent permitted by law.  Type "show copying"
    and "show warranty" for details.
    This GDB was configured as "x86_64-redhat-linux-gnu".
    For bug reporting instructions, please see:
    <http://www.gnu.org/software/gdb/bugs/>...
    Reading symbols from /usr/sbin/sshd...Reading symbols from /usr/lib/debug/usr/sbin/sshd.debug...done.
    done.
    BFD: Warning: /tmp/core/core-sshd-11-0-0-1347-1356793916 is truncated: expected core file size >= 806912, found: 802816.
    [New Thread 1347]
    Reading symbols from /lib64/libwrap.so.0...Reading symbols from /usr/lib/debug/lib64/libwrap.so.0.7.6.debug...done.
    done.
    Loaded symbols for /lib64/libwrap.so.0
    Reading symbols from /lib64/libpam.so.0...Reading symbols from /usr/lib/debug/lib64/libpam.so.0.81.5.debug...done.
    done.
    Loaded symbols for /lib64/libpam.so.0
    Reading symbols from /lib64/libdl.so.2...Reading symbols from /usr/lib/debug/lib64/libdl-2.5.so.debug...done.
    done.
    Loaded symbols for /lib64/libdl.so.2
    Reading symbols from /lib64/libselinux.so.1...
    warning: the debug information found in "/usr/lib/debug//lib64/libselinux.so.1.debug" does not match "/lib64/libselinux.so.1" (CRC mismatch).
    
    
    warning: the debug information found in "/usr/lib/debug/lib64/libselinux.so.1.debug" does not match "/lib64/libselinux.so.1" (CRC mismatch).
    
    (no debugging symbols found)...done.
    Loaded symbols for /lib64/libselinux.so.1
    Reading symbols from /lib64/libaudit.so.0...(no debugging symbols found)...done.
    Loaded symbols for /lib64/libaudit.so.0
    Reading symbols from /usr/lib64/libfipscheck.so.1...Reading symbols from /usr/lib/debug/usr/lib64/libfipscheck.so.1.1.0.debug...done.
    done.
    Loaded symbols for /usr/lib64/libfipscheck.so.1
    Reading symbols from /lib64/libcrypto.so.6...Reading symbols from /usr/lib/debug/lib64/libcrypto.so.0.9.8e.debug...done.
    done.
    Loaded symbols for /lib64/libcrypto.so.6
    Reading symbols from /lib64/libutil.so.1...Reading symbols from /usr/lib/debug/lib64/libutil-2.5.so.debug...done.
    done.
    Loaded symbols for /lib64/libutil.so.1
    Reading symbols from /lib64/libz.so.1...
    warning: the debug information found in "/usr/lib/debug//lib64/libz.so.1.2.3.debug" does not match "/lib64/libz.so.1" (CRC mismatch).
    
    
    warning: the debug information found in "/usr/lib/debug/lib64/libz.so.1.2.3.debug" does not match "/lib64/libz.so.1" (CRC mismatch).
    
    (no debugging symbols found)...done.
    Loaded symbols for /lib64/libz.so.1
    Reading symbols from /lib64/libnsl.so.1...Reading symbols from /usr/lib/debug/lib64/libnsl-2.5.so.debug...done.
    done.
    Loaded symbols for /lib64/libnsl.so.1
    Reading symbols from /lib64/libcrypt.so.1...Reading symbols from /usr/lib/debug/lib64/libcrypt-2.5.so.debug...done.
    done.
    Loaded symbols for /lib64/libcrypt.so.1
    Reading symbols from /lib64/libresolv.so.2...Reading symbols from /usr/lib/debug/lib64/libresolv-2.5.so.debug...done.
    done.
    Loaded symbols for /lib64/libresolv.so.2
    Reading symbols from /usr/lib64/libgssapi_krb5.so.2...Reading symbols from /usr/lib/debug/usr/lib64/libgssapi_krb5.so.2.2.debug...done.
    done.
    Loaded symbols for /usr/lib64/libgssapi_krb5.so.2
    Reading symbols from /usr/lib64/libkrb5.so.3...Reading symbols from /usr/lib/debug/usr/lib64/libkrb5.so.3.3.debug...done.
    done.
    Loaded symbols for /usr/lib64/libkrb5.so.3
    Reading symbols from /usr/lib64/libk5crypto.so.3...Reading symbols from /usr/lib/debug/usr/lib64/libk5crypto.so.3.1.debug...done.
    done.
    Loaded symbols for /usr/lib64/libk5crypto.so.3
    Reading symbols from /lib64/libcom_err.so.2...Reading symbols from /usr/lib/debug/lib64/libcom_err.so.2.1.debug...done.
    done.
    Loaded symbols for /lib64/libcom_err.so.2
    Reading symbols from /usr/lib64/libnss3.so...Reading symbols from /usr/lib/debug/usr/lib64/libnss3.so.debug...done.
    done.
    Loaded symbols for /usr/lib64/libnss3.so
    Reading symbols from /lib64/libc.so.6...Reading symbols from /usr/lib/debug/lib64/libc-2.5.so.debug...(no debugging symbols found)...done.
    (no debugging symbols found)...done.
    Loaded symbols for /lib64/libc.so.6
    Reading symbols from /lib64/ld-linux-x86-64.so.2...Reading symbols from /usr/lib/debug/lib64/ld-2.5.so.debug...done.
    done.
    Loaded symbols for /lib64/ld-linux-x86-64.so.2
    Reading symbols from /lib64/libsepol.so.1...Reading symbols from /usr/lib/debug/lib64/libsepol.so.1.debug...done.
    done.
    Loaded symbols for /lib64/libsepol.so.1
    Reading symbols from /usr/lib64/libkrb5support.so.0...Reading symbols from /usr/lib/debug/usr/lib64/libkrb5support.so.0.1.debug...done.
    done.
    Loaded symbols for /usr/lib64/libkrb5support.so.0
    Reading symbols from /lib64/libkeyutils.so.1...(no debugging symbols found)...done.
    Loaded symbols for /lib64/libkeyutils.so.1
    Reading symbols from /usr/lib64/libnssutil3.so...Reading symbols from /usr/lib/debug/usr/lib64/libnssutil3.so.debug...done.
    done.
    Loaded symbols for /usr/lib64/libnssutil3.so
    Reading symbols from /usr/lib64/libplc4.so...Reading symbols from /usr/lib/debug/usr/lib64/libplc4.so.debug...done.
    done.
    Loaded symbols for /usr/lib64/libplc4.so
    Reading symbols from /usr/lib64/libplds4.so...Reading symbols from /usr/lib/debug/usr/lib64/libplds4.so.debug...done.
    done.
    Loaded symbols for /usr/lib64/libplds4.so
    Reading symbols from /usr/lib64/libnspr4.so...Reading symbols from /usr/lib/debug/usr/lib64/libnspr4.so.debug...done.
    done.
    Loaded symbols for /usr/lib64/libnspr4.so
    Reading symbols from /lib64/libpthread.so.0...Reading symbols from /usr/lib/debug/lib64/libpthread-2.5.so.debug...done.
    [Thread debugging using libthread_db enabled]
    done.
    Loaded symbols for /lib64/libpthread.so.0
    Reading symbols from /lib64/libnss_files.so.2...Reading symbols from /usr/lib/debug/lib64/libnss_files-2.5.so.debug...done.
    done.
    Loaded symbols for /lib64/libnss_files.so.2
    Core was generated by `sshd: [accepted]              '.
    Program terminated with signal 11, Segmentation fault.
    #0  0x0000555550c798a0 in ?? ()
    (gdb) where
    #0  0x0000555550c798a0 in ?? ()
    #1  0x0000555555560b94 in sshd_exchange_identification (ac=<value optimized out>, av=<value optimized out>) at sshd.c:422
    #2  main (ac=<value optimized out>, av=<value optimized out>) at sshd.c:1721
    (gdb) thread apply all bt
    
    Thread 1 (Thread 0x2ada51905600 (LWP 1347)):
    #0  0x0000555550c798a0 in ?? ()
    #1  0x0000555555560b94 in sshd_exchange_identification (ac=<value optimized out>, av=<value optimized out>) at sshd.c:422
    #2  main (ac=<value optimized out>, av=<value optimized out>) at sshd.c:1721
    ### core of /usr/sbin/sshd running normally
    Code:
    # gdb /usr/sbin/sshd /tmp/core/core-sshd-11-0-0-1458-1356794096
    GNU gdb (GDB) CentOS (7.0.1-42.el5.centos.1)
    Copyright (C) 2009 Free Software Foundation, Inc.
    License GPLv3+: GNU GPL version 3 or later <http://gnu.org/licenses/gpl.html>
    This is free software: you are free to change and redistribute it.
    There is NO WARRANTY, to the extent permitted by law.  Type "show copying"
    and "show warranty" for details.
    This GDB was configured as "x86_64-redhat-linux-gnu".
    For bug reporting instructions, please see:
    <http://www.gnu.org/software/gdb/bugs/>...
    Reading symbols from /usr/sbin/sshd...Reading symbols from /usr/lib/debug/usr/sbin/sshd.debug...done.
    done.
    BFD: Warning: /tmp/core/core-sshd-11-0-0-1458-1356794096 is truncated: expected core file size >= 806912, found: 802816.
    [New Thread 1458]
    Reading symbols from /lib64/libwrap.so.0...Reading symbols from /usr/lib/debug/lib64/libwrap.so.0.7.6.debug...done.
    done.
    Loaded symbols for /lib64/libwrap.so.0
    Reading symbols from /lib64/libpam.so.0...Reading symbols from /usr/lib/debug/lib64/libpam.so.0.81.5.debug...done.
    done.
    Loaded symbols for /lib64/libpam.so.0
    Reading symbols from /lib64/libdl.so.2...Reading symbols from /usr/lib/debug/lib64/libdl-2.5.so.debug...done.
    done.
    Loaded symbols for /lib64/libdl.so.2
    Reading symbols from /lib64/libselinux.so.1...
    warning: the debug information found in "/usr/lib/debug//lib64/libselinux.so.1.debug" does not match "/lib64/libselinux.so.1" (CRC mismatch).
    
    
    warning: the debug information found in "/usr/lib/debug/lib64/libselinux.so.1.debug" does not match "/lib64/libselinux.so.1" (CRC mismatch).
    
    (no debugging symbols found)...done.
    Loaded symbols for /lib64/libselinux.so.1
    Reading symbols from /lib64/libaudit.so.0...(no debugging symbols found)...done.
    Loaded symbols for /lib64/libaudit.so.0
    Reading symbols from /usr/lib64/libfipscheck.so.1...Reading symbols from /usr/lib/debug/usr/lib64/libfipscheck.so.1.1.0.debug...done.
    done.
    Loaded symbols for /usr/lib64/libfipscheck.so.1
    Reading symbols from /lib64/libcrypto.so.6...Reading symbols from /usr/lib/debug/lib64/libcrypto.so.0.9.8e.debug...done.
    done.
    Loaded symbols for /lib64/libcrypto.so.6
    Reading symbols from /lib64/libutil.so.1...Reading symbols from /usr/lib/debug/lib64/libutil-2.5.so.debug...done.
    done.
    Loaded symbols for /lib64/libutil.so.1
    Reading symbols from /lib64/libz.so.1...
    warning: the debug information found in "/usr/lib/debug//lib64/libz.so.1.2.3.debug" does not match "/lib64/libz.so.1" (CRC mismatch).
    
    
    warning: the debug information found in "/usr/lib/debug/lib64/libz.so.1.2.3.debug" does not match "/lib64/libz.so.1" (CRC mismatch).
    
    (no debugging symbols found)...done.
    Loaded symbols for /lib64/libz.so.1
    Reading symbols from /lib64/libnsl.so.1...Reading symbols from /usr/lib/debug/lib64/libnsl-2.5.so.debug...done.
    done.
    Loaded symbols for /lib64/libnsl.so.1
    Reading symbols from /lib64/libcrypt.so.1...Reading symbols from /usr/lib/debug/lib64/libcrypt-2.5.so.debug...done.
    done.
    Loaded symbols for /lib64/libcrypt.so.1
    Reading symbols from /lib64/libresolv.so.2...Reading symbols from /usr/lib/debug/lib64/libresolv-2.5.so.debug...done.
    done.
    Loaded symbols for /lib64/libresolv.so.2
    Reading symbols from /usr/lib64/libgssapi_krb5.so.2...Reading symbols from /usr/lib/debug/usr/lib64/libgssapi_krb5.so.2.2.debug...done.
    done.
    Loaded symbols for /usr/lib64/libgssapi_krb5.so.2
    Reading symbols from /usr/lib64/libkrb5.so.3...Reading symbols from /usr/lib/debug/usr/lib64/libkrb5.so.3.3.debug...done.
    done.
    Loaded symbols for /usr/lib64/libkrb5.so.3
    Reading symbols from /usr/lib64/libk5crypto.so.3...Reading symbols from /usr/lib/debug/usr/lib64/libk5crypto.so.3.1.debug...done.
    done.
    Loaded symbols for /usr/lib64/libk5crypto.so.3
    Reading symbols from /lib64/libcom_err.so.2...Reading symbols from /usr/lib/debug/lib64/libcom_err.so.2.1.debug...done.
    done.
    Loaded symbols for /lib64/libcom_err.so.2
    Reading symbols from /usr/lib64/libnss3.so...Reading symbols from /usr/lib/debug/usr/lib64/libnss3.so.debug...done.
    done.
    Loaded symbols for /usr/lib64/libnss3.so
    Reading symbols from /lib64/libc.so.6...Reading symbols from /usr/lib/debug/lib64/libc-2.5.so.debug...(no debugging symbols found)...done.
    (no debugging symbols found)...done.
    Loaded symbols for /lib64/libc.so.6
    Reading symbols from /lib64/ld-linux-x86-64.so.2...Reading symbols from /usr/lib/debug/lib64/ld-2.5.so.debug...done.
    done.
    Loaded symbols for /lib64/ld-linux-x86-64.so.2
    Reading symbols from /lib64/libsepol.so.1...Reading symbols from /usr/lib/debug/lib64/libsepol.so.1.debug...done.
    done.
    Loaded symbols for /lib64/libsepol.so.1
    Reading symbols from /usr/lib64/libkrb5support.so.0...Reading symbols from /usr/lib/debug/usr/lib64/libkrb5support.so.0.1.debug...done.
    done.
    Loaded symbols for /usr/lib64/libkrb5support.so.0
    Reading symbols from /lib64/libkeyutils.so.1...(no debugging symbols found)...done.
    Loaded symbols for /lib64/libkeyutils.so.1
    Reading symbols from /usr/lib64/libnssutil3.so...Reading symbols from /usr/lib/debug/usr/lib64/libnssutil3.so.debug...done.
    done.
    Loaded symbols for /usr/lib64/libnssutil3.so
    Reading symbols from /usr/lib64/libplc4.so...Reading symbols from /usr/lib/debug/usr/lib64/libplc4.so.debug...done.
    done.
    Loaded symbols for /usr/lib64/libplc4.so
    Reading symbols from /usr/lib64/libplds4.so...Reading symbols from /usr/lib/debug/usr/lib64/libplds4.so.debug...done.
    done.
    Loaded symbols for /usr/lib64/libplds4.so
    Reading symbols from /usr/lib64/libnspr4.so...Reading symbols from /usr/lib/debug/usr/lib64/libnspr4.so.debug...done.
    done.
    Loaded symbols for /usr/lib64/libnspr4.so
    Reading symbols from /lib64/libpthread.so.0...Reading symbols from /usr/lib/debug/lib64/libpthread-2.5.so.debug...done.
    [Thread debugging using libthread_db enabled]
    done.
    Loaded symbols for /lib64/libpthread.so.0
    Reading symbols from /lib64/libnss_files.so.2...Reading symbols from /usr/lib/debug/lib64/libnss_files-2.5.so.debug...done.
    done.
    Loaded symbols for /lib64/libnss_files.so.2
    Core was generated by `sshd: [accepted] '.
    Program terminated with signal 11, Segmentation fault.
    #0  0x000055552746d8a0 in ?? ()
    (gdb) where
    #0  0x000055552746d8a0 in ?? ()
    #1  0x0000555555560b94 in sshd_exchange_identification (ac=<value optimized out>, av=<value optimized out>) at sshd.c:422
    #2  main (ac=<value optimized out>, av=<value optimized out>) at sshd.c:1721
    (gdb) thread apply all bt
    
    Thread 1 (Thread 0x2b13280f9600 (LWP 1458)):
    #0  0x000055552746d8a0 in ?? ()
    #1  0x0000555555560b94 in sshd_exchange_identification (ac=<value optimized out>, av=<value optimized out>) at sshd.c:422
    #2  main (ac=<value optimized out>, av=<value optimized out>) at sshd.c:1721
    ### core of /usr/bin/ssh - trying to connect to a remote systsm
    Code:
    # gdb /usr/bin/ssh /tmp/core/core-ssh-11-0-0-2798-1356794504
    GNU gdb (GDB) CentOS (7.0.1-42.el5.centos.1)
    Copyright (C) 2009 Free Software Foundation, Inc.
    License GPLv3+: GNU GPL version 3 or later <http://gnu.org/licenses/gpl.html>
    This is free software: you are free to change and redistribute it.
    There is NO WARRANTY, to the extent permitted by law.  Type "show copying"
    and "show warranty" for details.
    This GDB was configured as "x86_64-redhat-linux-gnu".
    For bug reporting instructions, please see:
    <http://www.gnu.org/software/gdb/bugs/>...
    Reading symbols from /usr/bin/ssh...Reading symbols from /usr/lib/debug/usr/bin/ssh.debug...done.
    done.
    [New Thread 2798]
    Reading symbols from /usr/lib64/libfipscheck.so.1...Reading symbols from /usr/lib/debug/usr/lib64/libfipscheck.so.1.1.0.debug...done.
    done.
    Loaded symbols for /usr/lib64/libfipscheck.so.1
    Reading symbols from /lib64/libcrypto.so.6...Reading symbols from /usr/lib/debug/lib64/libcrypto.so.0.9.8e.debug...done.
    done.
    Loaded symbols for /lib64/libcrypto.so.6
    Reading symbols from /lib64/libutil.so.1...Reading symbols from /usr/lib/debug/lib64/libutil-2.5.so.debug...done.
    done.
    Loaded symbols for /lib64/libutil.so.1
    Reading symbols from /lib64/libz.so.1...
    warning: the debug information found in "/usr/lib/debug//lib64/libz.so.1.2.3.debug" does not match "/lib64/libz.so.1" (CRC mismatch).
    
    
    warning: the debug information found in "/usr/lib/debug/lib64/libz.so.1.2.3.debug" does not match "/lib64/libz.so.1" (CRC mismatch).
    
    (no debugging symbols found)...done.
    Loaded symbols for /lib64/libz.so.1
    Reading symbols from /lib64/libnsl.so.1...Reading symbols from /usr/lib/debug/lib64/libnsl-2.5.so.debug...done.
    done.
    Loaded symbols for /lib64/libnsl.so.1
    Reading symbols from /lib64/libcrypt.so.1...Reading symbols from /usr/lib/debug/lib64/libcrypt-2.5.so.debug...done.
    done.
    Loaded symbols for /lib64/libcrypt.so.1
    Reading symbols from /lib64/libresolv.so.2...Reading symbols from /usr/lib/debug/lib64/libresolv-2.5.so.debug...done.
    done.
    Loaded symbols for /lib64/libresolv.so.2
    Reading symbols from /usr/lib64/libgssapi_krb5.so.2...Reading symbols from /usr/lib/debug/usr/lib64/libgssapi_krb5.so.2.2.debug...done.
    done.
    Loaded symbols for /usr/lib64/libgssapi_krb5.so.2
    Reading symbols from /usr/lib64/libkrb5.so.3...Reading symbols from /usr/lib/debug/usr/lib64/libkrb5.so.3.3.debug...done.
    done.
    Loaded symbols for /usr/lib64/libkrb5.so.3
    Reading symbols from /usr/lib64/libk5crypto.so.3...Reading symbols from /usr/lib/debug/usr/lib64/libk5crypto.so.3.1.debug...done.
    done.
    Loaded symbols for /usr/lib64/libk5crypto.so.3
    Reading symbols from /lib64/libcom_err.so.2...Reading symbols from /usr/lib/debug/lib64/libcom_err.so.2.1.debug...done.
    done.
    Loaded symbols for /lib64/libcom_err.so.2
    Reading symbols from /usr/lib64/libnss3.so...Reading symbols from /usr/lib/debug/usr/lib64/libnss3.so.debug...done.
    done.
    Loaded symbols for /usr/lib64/libnss3.so
    Reading symbols from /lib64/libc.so.6...Reading symbols from /usr/lib/debug/lib64/libc-2.5.so.debug...(no debugging symbols found)...done.
    (no debugging symbols found)...done.
    Loaded symbols for /lib64/libc.so.6
    Reading symbols from /usr/lib64/libplc4.so...Reading symbols from /usr/lib/debug/usr/lib64/libplc4.so.debug...done.
    done.
    Loaded symbols for /usr/lib64/libplc4.so
    Reading symbols from /lib64/libdl.so.2...Reading symbols from /usr/lib/debug/lib64/libdl-2.5.so.debug...done.
    done.
    Loaded symbols for /lib64/libdl.so.2
    Reading symbols from /usr/lib64/libkrb5support.so.0...Reading symbols from /usr/lib/debug/usr/lib64/libkrb5support.so.0.1.debug...done.
    done.
    Loaded symbols for /usr/lib64/libkrb5support.so.0
    Reading symbols from /lib64/libkeyutils.so.1...(no debugging symbols found)...done.
    Loaded symbols for /lib64/libkeyutils.so.1
    Reading symbols from /usr/lib64/libnssutil3.so...Reading symbols from /usr/lib/debug/usr/lib64/libnssutil3.so.debug...done.
    done.
    Loaded symbols for /usr/lib64/libnssutil3.so
    Reading symbols from /usr/lib64/libplds4.so...Reading symbols from /usr/lib/debug/usr/lib64/libplds4.so.debug...done.
    done.
    Loaded symbols for /usr/lib64/libplds4.so
    Reading symbols from /usr/lib64/libnspr4.so...Reading symbols from /usr/lib/debug/usr/lib64/libnspr4.so.debug...done.
    done.
    Loaded symbols for /usr/lib64/libnspr4.so
    Reading symbols from /lib64/libpthread.so.0...Reading symbols from /usr/lib/debug/lib64/libpthread-2.5.so.debug...done.
    [Thread debugging using libthread_db enabled]
    done.
    Loaded symbols for /lib64/libpthread.so.0
    Reading symbols from /lib64/ld-linux-x86-64.so.2...Reading symbols from /usr/lib/debug/lib64/ld-2.5.so.debug...done.
    done.
    Loaded symbols for /lib64/ld-linux-x86-64.so.2
    Reading symbols from /lib64/libselinux.so.1...
    warning: the debug information found in "/usr/lib/debug//lib64/libselinux.so.1.debug" does not match "/lib64/libselinux.so.1" (CRC mismatch).
    
    
    warning: the debug information found in "/usr/lib/debug/lib64/libselinux.so.1.debug" does not match "/lib64/libselinux.so.1" (CRC mismatch).
    
    (no debugging symbols found)...done.
    Loaded symbols for /lib64/libselinux.so.1
    Reading symbols from /lib64/libsepol.so.1...Reading symbols from /usr/lib/debug/lib64/libsepol.so.1.debug...done.
    done.
    Loaded symbols for /lib64/libsepol.so.1
    Reading symbols from /lib64/libnss_files.so.2...Reading symbols from /usr/lib/debug/lib64/libnss_files-2.5.so.debug...done.
    done.
    Loaded symbols for /lib64/libnss_files.so.2
    Core was generated by `ssh 10.0.0.120'.
    Program terminated with signal 11, Segmentation fault.
    #0  0x00005554e3f13b80 in ?? ()
    (gdb) where
    #0  0x00005554e3f13b80 in ?? ()
    #1  0x000055555557b67b in read_passphrase (
        prompt=0x7fffc930aa20 "The authenticity of host '10.0.0.120 (10.0.0.120)' can't be established.\nRSA key fingerprint is 2c:b9:58:40:6e:6a:e5:fb:1b:6e:e6:10:c3:fb:32:67.\nAre you sure you want to continue connecting (yes/no)? ", flags=1) at readpass.c:139
    #2  0x0000555555565f50 in confirm (
        prompt=0x7fffc930aa20 "The authenticity of host '10.0.0.120 (10.0.0.120)' can't be established.\nRSA key fingerprint is 2c:b9:58:40:6e:6a:e5:fb:1b:6e:e6:10:c3:fb:32:67.\nAre you sure you want to continue connecting (yes/no)? ") at sshconnect.c:567
    #3  0x0000555555566a36 in check_host_key (host=0x5555557b6e10 "10.0.0.120", hostaddr=<value optimized out>, host_key=0x5555557bdc30, readonly=0,
        user_hostfile=0x5555557b6cc0 "/root/.ssh/known_hosts", system_hostfile=0x5555557b6d70 "/etc/ssh/ssh_known_hosts") at sshconnect.c:772
    #4  0x000055555556781f in verify_host_key (host=0x5555557b6e10 "10.0.0.120", hostaddr=0x5555557a22a0, host_key=0x5555557bdc30) at sshconnect.c:964
    #5  0x000055555556b0f0 in verify_host_key_callback (hostkey=0x400) at sshconnect2.c:80
    #6  0x00005555555845cc in kexgex_client (kex=0x5555557bb540) at kexgexc.c:120
    #7  0x000055555558076d in kex_kexinit_finish (type=<value optimized out>, seq=<value optimized out>, ctxt=0x5555557bb540) at kex.c:241
    #8  kex_input_kexinit (type=<value optimized out>, seq=<value optimized out>, ctxt=0x5555557bb540) at kex.c:210
    #9  0x000055555557fabd in dispatch_run (mode=0, done=0x5555557bb5a8, ctxt=0x5555557bb540) at dispatch.c:93
    #10 0x000055555556b04e in ssh_kex2 (host=<value optimized out>, hostaddr=<value optimized out>) at sshconnect2.c:142
    #11 0x0000555555565be0 in ssh_login (sensitive=0x5555557a2320, orighost=<value optimized out>, hostaddr=0x5555557a22a0, pw=<value optimized out>,
        timeout_ms=-1000) at sshconnect.c:1000
    #12 0x000055555555e1ca in main (ac=<value optimized out>, av=<value optimized out>) at ssh.c:762
    (gdb) thread apply all bt
    
    Thread 1 (Thread 0x2b0ee4df8e20 (LWP 2798)):
    #0  0x00005554e3f13b80 in ?? ()
    #1  0x000055555557b67b in read_passphrase (
        prompt=0x7fffc930aa20 "The authenticity of host '10.0.0.120 (10.0.0.120)' can't be established.\nRSA key fingerprint is 2c:b9:58:40:6e:6a:e5:fb:1b:6e:e6:10:c3:fb:32:67.\nAre you sure you want to continue connecting (yes/no)? ", flags=1) at readpass.c:139
    #2  0x0000555555565f50 in confirm (
        prompt=0x7fffc930aa20 "The authenticity of host '10.0.0.120 (10.0.0.120)' can't be established.\nRSA key fingerprint is 2c:b9:58:40:6e:6a:e5:fb:1b:6e:e6:10:c3:fb:32:67.\nAre you sure you want to continue connecting (yes/no)? ") at sshconnect.c:567
    #3  0x0000555555566a36 in check_host_key (host=0x5555557b6e10 "10.0.0.120", hostaddr=<value optimized out>, host_key=0x5555557bdc30, readonly=0,
        user_hostfile=0x5555557b6cc0 "/root/.ssh/known_hosts", system_hostfile=0x5555557b6d70 "/etc/ssh/ssh_known_hosts") at sshconnect.c:772
    #4  0x000055555556781f in verify_host_key (host=0x5555557b6e10 "10.0.0.120", hostaddr=0x5555557a22a0, host_key=0x5555557bdc30) at sshconnect.c:964
    #5  0x000055555556b0f0 in verify_host_key_callback (hostkey=0x400) at sshconnect2.c:80
    #6  0x00005555555845cc in kexgex_client (kex=0x5555557bb540) at kexgexc.c:120
    #7  0x000055555558076d in kex_kexinit_finish (type=<value optimized out>, seq=<value optimized out>, ctxt=0x5555557bb540) at kex.c:241
    #8  kex_input_kexinit (type=<value optimized out>, seq=<value optimized out>, ctxt=0x5555557bb540) at kex.c:210
    #9  0x000055555557fabd in dispatch_run (mode=0, done=0x5555557bb5a8, ctxt=0x5555557bb540) at dispatch.c:93
    #10 0x000055555556b04e in ssh_kex2 (host=<value optimized out>, hostaddr=<value optimized out>) at sshconnect2.c:142
    #11 0x0000555555565be0 in ssh_login (sensitive=0x5555557a2320, orighost=<value optimized out>, hostaddr=0x5555557a22a0, pw=<value optimized out>,
        timeout_ms=-1000) at sshconnect.c:1000
    #12 0x000055555555e1ca in main (ac=<value optimized out>, av=<value optimized out>) at ssh.c:762
    Not sure what package(s) might be broken but I figured I'd try rpm -V[K] on a handful of them...

    Code:
    # rpm -V openssh
    .M......    /usr/libexec/openssh/ssh-keysign
    # rpm -V openssh-server
    # rpm -V openssh-clients
    # rpm -V openssl
    # rpm -VK tcp_wrappers pam glibc libselinux audit-libs fipscheck openssl zlib e2fsprogs nss libsepol nspr openssh-clients openssh-server openssh
    S.5.....  c /etc/pam.d/system-auth
    S.5.....  c /etc/pam.d/system-auth
    .M......    /usr/libexec/openssh/ssh-keysign
    I tried reinstalling, uninstalling/installing openssh-server & openssh-clients and repair installs on the packages above.

    I don't dare try to uninstall/reinstall openssl or do a `yum reinstall *` as I'm worried that's going to do more harm than good!

    ### strace -o /tmp/core/strace_sshd.txt /usr/sbin/sshd -dddDp 19999
    Code:
    execve("/usr/sbin/sshd", ["/usr/sbin/sshd", "-dddDp", "19999"], [/* 25 vars */]) = 0
    brk(0)                                  = 0x5555557c1000
    mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x2b9e50c92000
    uname({sys="Linux", node="daniel.itforesight.net", ...}) = 0
    access("/etc/ld.so.preload", R_OK)      = -1 ENOENT (No such file or directory)
    open("/etc/ld.so.cache", O_RDONLY)      = 3
    fstat(3, {st_mode=S_IFREG|0644, st_size=47439, ...}) = 0
    mmap(NULL, 47439, PROT_READ, MAP_PRIVATE, 3, 0) = 0x2b9e50c93000
    close(3)                                = 0
    open("/lib64/libwrap.so.0", O_RDONLY)   = 3
    read(3, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\340-\0\0\0\0\0\0"..., 832) = 832
    fstat(3, {st_mode=S_IFREG|0755, st_size=35072, ...}) = 0
    mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x2b9e50c9f000
    mmap(NULL, 2132648, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0x2b9e50e94000
    mprotect(0x2b9e50e9c000, 2093056, PROT_NONE) = 0
    mmap(0x2b9e5109b000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x7000) = 0x2b9e5109b000
    close(3)                                = 0
    open("/lib64/libpam.so.0", O_RDONLY)    = 3
    read(3, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\300$\0\0\0\0\0\0"..., 832) = 832
    fstat(3, {st_mode=S_IFREG|0755, st_size=44472, ...}) = 0
    mmap(NULL, 2140040, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0x2b9e5109d000
    mprotect(0x2b9e510a8000, 2093056, PROT_NONE) = 0
    mmap(0x2b9e512a7000, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0xa000) = 0x2b9e512a7000
    close(3)                                = 0
    open("/lib64/libdl.so.2", O_RDONLY)     = 3
    read(3, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\20\16\0\0\0\0\0\0"..., 832) = 832
    fstat(3, {st_mode=S_IFREG|0755, st_size=20424, ...}) = 0
    mmap(NULL, 2109696, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0x2b9e512a8000
    mprotect(0x2b9e512aa000, 2097152, PROT_NONE) = 0
    mmap(0x2b9e514aa000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x2000) = 0x2b9e514aa000
    close(3)                                = 0
    open("/lib64/libselinux.so.1", O_RDONLY) = 3
    read(3, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\340E\0\0\0\0\0\0"..., 832) = 832
    fstat(3, {st_mode=S_IFREG|0755, st_size=92960, ...}) = 0
    mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x2b9e514ac000
    mmap(NULL, 2192800, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0x2b9e514ad000
    mprotect(0x2b9e514c2000, 2097152, PROT_NONE) = 0
    mmap(0x2b9e516c2000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x15000) = 0x2b9e516c2000
    mmap(0x2b9e516c4000, 1440, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_ANONYMOUS, -1, 0) = 0x2b9e516c4000
    close(3)                                = 0
    open("/lib64/libaudit.so.0", O_RDONLY)  = 3
    read(3, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\340&\0\0\0\0\0\0"..., 832) = 832
    fstat(3, {st_mode=S_IFREG|0755, st_size=96600, ...}) = 0
    mmap(NULL, 2191888, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0x2b9e516c5000
    mprotect(0x2b9e516dc000, 2093056, PROT_NONE) = 0
    mmap(0x2b9e518db000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x16000) = 0x2b9e518db000
    close(3)                                = 0
    open("/usr/lib64/libfipscheck.so.1", O_RDONLY) = 3
    read(3, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\300\n\0\0\0\0\0\0"..., 832) = 832
    fstat(3, {st_mode=S_IFREG|0755, st_size=6680, ...}) = 0
    mmap(NULL, 2102008, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0x2b9e518dd000
    mprotect(0x2b9e518df000, 2093056, PROT_NONE) = 0
    mmap(0x2b9e51ade000, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x1000) = 0x2b9e51ade000
    close(3)                                = 0
    open("/lib64/libcrypto.so.6", O_RDONLY) = 3
    read(3, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\300\232\5\0\0\0\0\0"..., 832) = 832
    fstat(3, {st_mode=S_IFREG|0755, st_size=1364912, ...}) = 0
    mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x2b9e51adf000
    mmap(NULL, 3476304, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0x2b9e51ae0000
    mprotect(0x2b9e51c0d000, 2093056, PROT_NONE) = 0
    mmap(0x2b9e51e0c000, 135168, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x12c000) = 0x2b9e51e0c000
    mmap(0x2b9e51e2d000, 15184, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_ANONYMOUS, -1, 0) = 0x2b9e51e2d000
    close(3)                                = 0
    open("/lib64/libutil.so.1", O_RDONLY)   = 3
    read(3, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\200\16\0\0\0\0\0\0"..., 832) = 832
    fstat(3, {st_mode=S_IFREG|0755, st_size=15280, ...}) = 0
    mmap(NULL, 2105616, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0x2b9e51e31000
    mprotect(0x2b9e51e33000, 2093056, PROT_NONE) = 0
    mmap(0x2b9e52032000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x1000) = 0x2b9e52032000
    close(3)                                = 0
    open("/lib64/libz.so.1", O_RDONLY)      = 3
    read(3, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\220\36\0\0\0\0\0\0"..., 832) = 832
    fstat(3, {st_mode=S_IFREG|0755, st_size=83280, ...}) = 0
    mmap(NULL, 2178544, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0x2b9e52034000
    mprotect(0x2b9e52048000, 2093056, PROT_NONE) = 0
    mmap(0x2b9e52247000, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x13000) = 0x2b9e52247000
    close(3)                                = 0
    open("/lib64/libnsl.so.1", O_RDONLY)    = 3
    read(3, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\240@\0\0\0\0\0\0"..., 832) = 832
    fstat(3, {st_mode=S_IFREG|0755, st_size=111480, ...}) = 0
    mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x2b9e52248000
    mmap(NULL, 2194096, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0x2b9e52249000
    mprotect(0x2b9e5225e000, 2093056, PROT_NONE) = 0
    mmap(0x2b9e5245d000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x14000) = 0x2b9e5245d000
    mmap(0x2b9e5245f000, 6832, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_ANONYMOUS, -1, 0) = 0x2b9e5245f000
    close(3)                                = 0
    open("/lib64/libcrypt.so.1", O_RDONLY)  = 3
    read(3, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\360\t\0\0\0\0\0\0"..., 832) = 832
    fstat(3, {st_mode=S_IFREG|0755, st_size=45728, ...}) = 0
    mmap(NULL, 2322880, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0x2b9e52461000
    mprotect(0x2b9e5246a000, 2093056, PROT_NONE) = 0
    mmap(0x2b9e52669000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x8000) = 0x2b9e52669000
    mmap(0x2b9e5266b000, 184768, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_ANONYMOUS, -1, 0) = 0x2b9e5266b000
    close(3)                                = 0
    open("/lib64/libresolv.so.2", O_RDONLY) = 3
    read(3, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\0203\0\0\0\0\0\0"..., 832) = 832
    fstat(3, {st_mode=S_IFREG|0755, st_size=89880, ...}) = 0
    mmap(NULL, 2181896, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0x2b9e52699000
    mprotect(0x2b9e526aa000, 2097152, PROT_NONE) = 0
    mmap(0x2b9e528aa000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x11000) = 0x2b9e528aa000
    mmap(0x2b9e528ac000, 6920, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_ANONYMOUS, -1, 0) = 0x2b9e528ac000
    close(3)                                = 0
    open("/usr/lib64/libgssapi_krb5.so.2", O_RDONLY) = 3
    read(3, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\0\222\0\0\0\0\0\0"..., 832) = 832
    fstat(3, {st_mode=S_IFREG|0755, st_size=188328, ...}) = 0
    mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x2b9e528ae000
    mmap(NULL, 2283888, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0x2b9e528af000
    mprotect(0x2b9e528db000, 2097152, PROT_NONE) = 0
    mmap(0x2b9e52adb000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x2c000) = 0x2b9e52adb000
    close(3)                                = 0
    open("/usr/lib64/libkrb5.so.3", O_RDONLY) = 3
    read(3, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\320\222\1\0\0\0\0\0"..., 832) = 832
    fstat(3, {st_mode=S_IFREG|0755, st_size=611312, ...}) = 0
    mmap(NULL, 2706656, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0x2b9e52add000
    mprotect(0x2b9e52b6e000, 2097152, PROT_NONE) = 0
    mmap(0x2b9e52d6e000, 16384, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x91000) = 0x2b9e52d6e000
    close(3)                                = 0
    open("/usr/lib64/libk5crypto.so.3", O_RDONLY) = 3
    read(3, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\260V\0\0\0\0\0\0"..., 832) = 832
    fstat(3, {st_mode=S_IFREG|0755, st_size=151176, ...}) = 0
    mmap(NULL, 2247528, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0x2b9e52d72000
    mprotect(0x2b9e52d96000, 2093056, PROT_NONE) = 0
    mmap(0x2b9e52f95000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x23000) = 0x2b9e52f95000
    close(3)                                = 0
    open("/lib64/libcom_err.so.2", O_RDONLY) = 3
    read(3, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\320\n\0\0\0\0\0\0"..., 832) = 832
    fstat(3, {st_mode=S_IFREG|0755, st_size=7832, ...}) = 0
    mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x2b9e52f97000
    mmap(NULL, 2103144, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0x2b9e52f98000
    mprotect(0x2b9e52f9a000, 2093056, PROT_NONE) = 0
    mmap(0x2b9e53199000, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x1000) = 0x2b9e53199000
    close(3)                                = 0
    open("/usr/lib64/libnss3.so", O_RDONLY) = 3
    read(3, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\220\211\1\0\0\0\0\0"..., 832) = 832
    fstat(3, {st_mode=S_IFREG|0755, st_size=1232280, ...}) = 0
    mmap(NULL, 3333416, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0x2b9e5319a000
    mprotect(0x2b9e532c1000, 2093056, PROT_NONE) = 0
    mmap(0x2b9e534c0000, 28672, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x126000) = 0x2b9e534c0000
    mmap(0x2b9e534c7000, 3368, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_ANONYMOUS, -1, 0) = 0x2b9e534c7000
    close(3)                                = 0
    open("/lib64/libc.so.6", O_RDONLY)      = 3
    read(3, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\220\332\1\0\0\0\0\0"..., 832) = 832
    fstat(3, {st_mode=S_IFREG|0755, st_size=1712648, ...}) = 0
    mmap(NULL, 3498328, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0x2b9e534c8000
    mprotect(0x2b9e53616000, 2093056, PROT_NONE) = 0
    mmap(0x2b9e53815000, 20480, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x14d000) = 0x2b9e53815000
    mmap(0x2b9e5381a000, 16728, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_ANONYMOUS, -1, 0) = 0x2b9e5381a000
    close(3)                                = 0
    open("/lib64/libsepol.so.1", O_RDONLY)  = 3
    read(3, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0@=\0\0\0\0\0\0"..., 832) = 832
    fstat(3, {st_mode=S_IFREG|0755, st_size=245232, ...}) = 0
    mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x2b9e5381f000
    mmap(NULL, 2383168, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0x2b9e53820000
    mprotect(0x2b9e5385b000, 2097152, PROT_NONE) = 0
    mmap(0x2b9e53a5b000, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x3b000) = 0x2b9e53a5b000
    mmap(0x2b9e53a5c000, 40256, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_ANONYMOUS, -1, 0) = 0x2b9e53a5c000
    close(3)                                = 0
    open("/usr/lib64/libkrb5support.so.0", O_RDONLY) = 3
    read(3, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\360\"\0\0\0\0\0\0"..., 832) = 832
    fstat(3, {st_mode=S_IFREG|0755, st_size=33480, ...}) = 0
    mmap(NULL, 2128848, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0x2b9e53a66000
    mprotect(0x2b9e53a6e000, 2093056, PROT_NONE) = 0
    mmap(0x2b9e53c6d000, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x7000) = 0x2b9e53c6d000
    close(3)                                = 0
    open("/lib64/libkeyutils.so.1", O_RDONLY) = 3
    read(3, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0` \0\0\0\0\0\0"..., 832) = 832
    fstat(3, {st_mode=S_IFREG|0755, st_size=32256, ...}) = 0
    mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x2b9e53c6e000
    mmap(NULL, 2140576, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0x2b9e53c6f000
    mprotect(0x2b9e53c76000, 2097152, PROT_NONE) = 0
    mmap(0x2b9e53e76000, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x7000) = 0x2b9e53e76000
    mmap(0x2b9e53e77000, 10656, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_ANONYMOUS, -1, 0) = 0x2b9e53e77000
    close(3)                                = 0
    open("/usr/lib64/libnssutil3.so", O_RDONLY) = 3
    read(3, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\240\250\0\0\0\0\0\0"..., 832) = 832
    fstat(3, {st_mode=S_IFREG|0755, st_size=151592, ...}) = 0
    mmap(NULL, 2248256, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0x2b9e53e7a000
    mprotect(0x2b9e53e99000, 2097152, PROT_NONE) = 0
    mmap(0x2b9e54099000, 24576, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x1f000) = 0x2b9e54099000
    close(3)                                = 0
    open("/usr/lib64/libplc4.so", O_RDONLY) = 3
    read(3, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0p\23\0\0\0\0\0\0"..., 832) = 832
    fstat(3, {st_mode=S_IFREG|0755, st_size=15624, ...}) = 0
    mmap(NULL, 2110904, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0x2b9e5409f000
    mprotect(0x2b9e540a3000, 2093056, PROT_NONE) = 0
    mmap(0x2b9e542a2000, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x3000) = 0x2b9e542a2000
    close(3)                                = 0
    open("/usr/lib64/libplds4.so", O_RDONLY) = 3
    read(3, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0@\16\0\0\0\0\0\0"..., 832) = 832
    fstat(3, {st_mode=S_IFREG|0755, st_size=11624, ...}) = 0
    mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x2b9e542a3000
    mmap(NULL, 2106928, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0x2b9e542a4000
    mprotect(0x2b9e542a7000, 2093056, PROT_NONE) = 0
    mmap(0x2b9e544a6000, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x2000) = 0x2b9e544a6000
    close(3)                                = 0
    open("/usr/lib64/libnspr4.so", O_RDONLY) = 3
    read(3, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\0\320\0\0\0\0\0\0"..., 832) = 832
    fstat(3, {st_mode=S_IFREG|0755, st_size=230808, ...}) = 0
    mmap(NULL, 2336608, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0x2b9e544a7000
    mprotect(0x2b9e544dd000, 2097152, PROT_NONE) = 0
    mmap(0x2b9e546dd000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x36000) = 0x2b9e546dd000
    mmap(0x2b9e546df000, 10080, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_ANONYMOUS, -1, 0) = 0x2b9e546df000
    close(3)                                = 0
    open("/lib64/libpthread.so.0", O_RDONLY) = 3
    read(3, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\340W\0\0\0\0\0\0"..., 832) = 832
    fstat(3, {st_mode=S_IFREG|0755, st_size=142744, ...}) = 0
    mmap(NULL, 2204528, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0x2b9e546e2000
    mprotect(0x2b9e546f8000, 2093056, PROT_NONE) = 0
    mmap(0x2b9e548f7000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x15000) = 0x2b9e548f7000
    mmap(0x2b9e548f9000, 13168, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_ANONYMOUS, -1, 0) = 0x2b9e548f9000
    close(3)                                = 0
    mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x2b9e548fd000
    mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x2b9e548fe000
    mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x2b9e548ff000
    arch_prctl(ARCH_SET_FS, 0x2b9e548ff600) = 0
    mprotect(0x2b9e548f7000, 4096, PROT_READ) = 0
    mprotect(0x2b9e53815000, 16384, PROT_READ) = 0
    mprotect(0x2b9e528aa000, 4096, PROT_READ) = 0
    mprotect(0x2b9e52669000, 4096, PROT_READ) = 0
    mprotect(0x2b9e5245d000, 4096, PROT_READ) = 0
    mprotect(0x2b9e52032000, 4096, PROT_READ) = 0
    mprotect(0x2b9e514aa000, 4096, PROT_READ) = 0
    mprotect(0x2b9e50e92000, 4096, PROT_READ) = 0
    munmap(0x2b9e50c93000, 47439)           = 0
    set_tid_address(0x2b9e548ff690)         = 9751
    set_robust_list(0x2b9e548ff6a0, 0x18)   = 0
    futex(0x7fff59e3360c, FUTEX_WAKE_PRIVATE, 1) = -1 ENOSYS (Function not implemented)
    rt_sigaction(SIGRTMIN, {0x2b9e546e73c0, [], SA_RESTORER|SA_SIGINFO, 0x2b9e546f0be0}, NULL, 8) = 0
    rt_sigaction(SIGRT_1, {0x2b9e546e72f0, [], SA_RESTORER|SA_RESTART|SA_SIGINFO, 0x2b9e546f0be0}, NULL, 8) = 0
    rt_sigprocmask(SIG_UNBLOCK, [RTMIN RT_1], NULL, 8) = 0
    getrlimit(RLIMIT_STACK, {rlim_cur=8192*1024, rlim_max=8192*1024}) = 0
    futex(0x2b9e514ab0ec, FUTEX_WAKE, 2147483647) = 0
    brk(0)                                  = 0x5555557c1000
    brk(0x5555557e2000)                     = 0x5555557e2000
    mprotect(0x5555557b6000, 4096, PROT_READ|PROT_WRITE) = 0
    mprotect(0x555555576000, 4096, PROT_READ|PROT_WRITE|PROT_EXEC) = 0
    mprotect(0x555555576000, 4096, PROT_READ|PROT_EXEC) = 0
    mprotect(0x5555557b6000, 4096, PROT_READ|PROT_WRITE) = 0
    mprotect(0x5555557b6000, 4096, PROT_READ|PROT_WRITE) = 0
    mprotect(0x5555557b6000, 4096, PROT_READ|PROT_WRITE) = 0
    mprotect(0x5555557b6000, 4096, PROT_READ|PROT_WRITE) = 0
    mprotect(0x5555557b6000, 4096, PROT_READ|PROT_WRITE) = 0
    mprotect(0x555555560000, 4096, PROT_READ|PROT_WRITE|PROT_EXEC) = 0
    mprotect(0x555555560000, 4096, PROT_READ|PROT_EXEC) = 0
    mprotect(0x555555576000, 4096, PROT_READ|PROT_WRITE|PROT_EXEC) = 0
    mprotect(0x555555576000, 4096, PROT_READ|PROT_EXEC) = 0
    mprotect(0x55555557b000, 4096, PROT_READ|PROT_WRITE|PROT_EXEC) = 0
    mprotect(0x55555557b000, 4096, PROT_READ|PROT_EXEC) = 0
    access("/etc/selinux/", F_OK)           = 0
    open("/etc/selinux/config", O_RDONLY)   = -1 ENOENT (No such file or directory)
    open("/proc/mounts", O_RDONLY)          = 3
    fstat(3, {st_mode=S_IFREG|0444, st_size=0, ...}) = 0
    mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x2b9e50c93000
    read(3, "rootfs / rootfs rw 0 0\n/dev/root"..., 1024) = 534
    close(3)                                = 0
    munmap(0x2b9e50c93000, 4096)            = 0
    open("/selinux/mls", O_RDONLY)          = 3
    read(3, "0", 19)                        = 1
    close(3)                                = 0
    open("/proc/sys/crypto/fips_enabled", O_RDONLY) = -1 ENOENT (No such file or directory)
    open("/etc/pki/tls/openssl.cnf", O_RDONLY) = 3
    fstat(3, {st_mode=S_IFREG|0644, st_size=9828, ...}) = 0
    mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x2b9e50c93000
    read(3, "#\n# OpenSSL example configuratio"..., 4096) = 4096
    read(3, "trings).\n# MASK:XXXX a literal m"..., 4096) = 4096
    read(3, "dentifier=keyid:always,issuer:al"..., 4096) = 1636
    read(3, "", 4096)                       = 0
    close(3)                                = 0
    munmap(0x2b9e50c93000, 4096)            = 0
    geteuid()                               = 0
    setgroups(0, [])                        = 0
    open("/dev/null", O_RDWR)               = 3
    close(3)                                = 0
    open("/proc/9751/fd", O_RDONLY|O_NONBLOCK|O_DIRECTORY) = 3
    fcntl(3, F_SETFD, FD_CLOEXEC)           = 0
    getdents(3, /* 6 entries */, 32768)     = 144
    getdents(3, /* 0 entries */, 32768)     = 0
    close(3)                                = 0
    write(2, "debug2: load_server_config: file"..., 59) = 59
    open("/etc/ssh/sshd_config", O_RDONLY)  = 3
    fstat(3, {st_mode=S_IFREG|0600, st_size=3332, ...}) = 0
    mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x2b9e50c93000
    read(3, "#\t$OpenBSD: sshd_config,v 1.73 2"..., 4096) = 3332
    read(3, "", 4096)                       = 0
    close(3)                                = 0
    munmap(0x2b9e50c93000, 4096)            = 0
    write(2, "debug2: load_server_config: done"..., 51) = 51
    write(2, "debug2: parse_server_config: con"..., 66) = 66
    stat("/dev/urandom", {st_mode=S_IFCHR|0444, st_rdev=makedev(1, 9), ...}) = 0
    open("/dev/urandom", O_RDONLY)          = 3
    read(3, ";W\3465N\357", 6)              = 6
    close(3)                                = 0
    open("/dev/urandom", O_RDONLY|O_NOCTTY|O_NONBLOCK) = 3
    fstat(3, {st_mode=S_IFCHR|0444, st_rdev=makedev(1, 9), ...}) = 0
    poll([{fd=3, events=POLLIN}], 1, 10)    = 1 ([{fd=3, revents=POLLIN}])
    read(3, "7jg\221_U\241y\365f/\3462#q\0\2306\235\265o*oi\355\201\341(\337C\252\20"..., 48) = 48
    close(3)                                = 0
    getuid()                                = 0
    time(NULL)                              = 1356837333
    open("/etc/gai.conf", O_RDONLY)         = -1 ENOENT (No such file or directory)
    futex(0x2b9e5381ba08, FUTEX_WAKE, 2147483647) = 0
    socket(PF_NETLINK, SOCK_RAW, 0)         = 3
    bind(3, {sa_family=AF_NETLINK, pid=0, groups=00000000}, 12) = 0
    getsockname(3, {sa_family=AF_NETLINK, pid=9751, groups=00000000}, [6477061164860702732]) = 0
    time(NULL)                              = 1356837333
    sendto(3, "\24\0\0\0\26\0\1\3\325\261\337P\0\0\0\0\0\0\0\0", 20, 0, {sa_family=AF_NETLINK, pid=0, groups=00000000}, 12) = 20
    recvmsg(3, {msg_name(12)={sa_family=AF_NETLINK, pid=0, groups=00000000}, msg_iov(1)=[{"<\0\0\0\24\0\2\0\325\261\337P\27&\0\0\2\10\200\376\1\0\0\0\10\0\1\0\177\0\0\1"..., 4096}], msg_controllen=0, msg_flags=0}, 0) = 332
    recvmsg(3, {msg_name(12)={sa_family=AF_NETLINK, pid=0, groups=00000000}, msg_iov(1)=[{"\24\0\0\0\3\0\2\0\325\261\337P\27&\0\0\0\0\0\0\1\0\0\0\10\0\1\0\177\0\0\1"..., 4096}], msg_controllen=0, msg_flags=0}, 0) = 20
    close(3)                                = 0
    socket(PF_INET6, SOCK_DGRAM, IPPROTO_IP) = -1 EAFNOSUPPORT (Address family not supported by protocol)
    socket(PF_INET, SOCK_DGRAM, IPPROTO_IP) = 3
    connect(3, {sa_family=AF_INET, sin_port=htons(19999), sin_addr=inet_addr("0.0.0.0")}, 16) = 0
    getsockname(3, {sa_family=AF_INET, sin_port=htons(33406), sin_addr=inet_addr("127.0.0.1")}, [8589934608]) = 0
    close(3)                                = 0
    write(2, "debug1: sshd version OpenSSH_4.3"..., 36) = 36
    socket(PF_FILE, SOCK_STREAM, 0)         = 3
    fcntl(3, F_SETFL, O_RDWR|O_NONBLOCK)    = 0
    connect(3, {sa_family=AF_FILE, path="/var/run/nscd/socket"...}, 110) = -1 ENOENT (No such file or directory)
    close(3)                                = 0
    socket(PF_FILE, SOCK_STREAM, 0)         = 3
    fcntl(3, F_SETFL, O_RDWR|O_NONBLOCK)    = 0
    connect(3, {sa_family=AF_FILE, path="/var/run/nscd/socket"...}, 110) = -1 ENOENT (No such file or directory)
    close(3)                                = 0
    open("/etc/nsswitch.conf", O_RDONLY)    = 3
    fstat(3, {st_mode=S_IFREG|0644, st_size=1717, ...}) = 0
    mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x2b9e50c93000
    read(3, "#\n# /etc/nsswitch.conf\n#\n# An ex"..., 4096) = 1717
    read(3, "", 4096)                       = 0
    close(3)                                = 0
    munmap(0x2b9e50c93000, 4096)            = 0
    open("/etc/ld.so.cache", O_RDONLY)      = 3
    fstat(3, {st_mode=S_IFREG|0644, st_size=47439, ...}) = 0
    mmap(NULL, 47439, PROT_READ, MAP_PRIVATE, 3, 0) = 0x2b9e50c93000
    close(3)                                = 0
    open("/lib64/libnss_files.so.2", O_RDONLY) = 3
    read(3, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\340\37\0\0\0\0\0\0"..., 832) = 832
    fstat(3, {st_mode=S_IFREG|0755, st_size=53880, ...}) = 0
    mmap(NULL, 2139432, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0x2b9e54900000
    mprotect(0x2b9e5490a000, 2093056, PROT_NONE) = 0
    mmap(0x2b9e54b09000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x9000) = 0x2b9e54b09000
    close(3)                                = 0
    mprotect(0x2b9e54b09000, 4096, PROT_READ) = 0
    munmap(0x2b9e50c93000, 47439)           = 0
    open("/etc/passwd", O_RDONLY)           = 3
    fcntl(3, F_GETFD)                       = 0
    fcntl(3, F_SETFD, FD_CLOEXEC)           = 0
    fstat(3, {st_mode=S_IFREG|0644, st_size=3120, ...}) = 0
    mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x2b9e50c93000
    read(3, "root:x:0:0:root:/root:/bin/bash\n"..., 4096) = 3120
    close(3)                                = 0
    munmap(0x2b9e50c93000, 4096)            = 0
    open("/etc/ssh/ssh_host_rsa_key", O_RDONLY) = 3
    fstat(3, {st_mode=S_IFREG|0600, st_size=1675, ...}) = 0
    getuid()                                = 0
    fstat(3, {st_mode=S_IFREG|0600, st_size=1675, ...}) = 0
    read(3, "-----BEGIN RSA PRIVATE KEY-----\n"..., 1675) = 1675
    write(2, "debug3: Not a RSA1 key file /etc"..., 56) = 56
    lseek(3, 0, SEEK_SET)                   = 0
    fcntl(3, F_GETFL)                       = 0x8000 (flags O_RDONLY|O_LARGEFILE)
    fstat(3, {st_mode=S_IFREG|0600, st_size=1675, ...}) = 0
    mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x2b9e50c93000
    lseek(3, 0, SEEK_CUR)                   = 0
    read(3, "-----BEGIN RSA PRIVATE KEY-----\n"..., 4096) = 1675
    time([1356837333])                      = 1356837333
    time([1356837333])                      = 1356837333
    close(3)                                = 0
    munmap(0x2b9e50c93000, 4096)            = 0
    write(2, "debug1: read PEM private key don"..., 45) = 45
    write(2, "debug1: private host key: #0 typ"..., 41) = 41
    open("/etc/ssh/ssh_host_dsa_key", O_RDONLY) = 3
    fstat(3, {st_mode=S_IFREG|0600, st_size=668, ...}) = 0
    getuid()                                = 0
    fstat(3, {st_mode=S_IFREG|0600, st_size=668, ...}) = 0
    read(3, "-----BEGIN DSA PRIVATE KEY-----\n"..., 668) = 668
    write(2, "debug3: Not a RSA1 key file /etc"..., 56) = 56
    lseek(3, 0, SEEK_SET)                   = 0
    fcntl(3, F_GETFL)                       = 0x8000 (flags O_RDONLY|O_LARGEFILE)
    fstat(3, {st_mode=S_IFREG|0600, st_size=668, ...}) = 0
    mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x2b9e50c93000
    lseek(3, 0, SEEK_CUR)                   = 0
    read(3, "-----BEGIN DSA PRIVATE KEY-----\n"..., 4096) = 668
    close(3)                                = 0
    munmap(0x2b9e50c93000, 4096)            = 0
    write(2, "debug1: read PEM private key don"..., 45) = 45
    write(2, "debug1: private host key: #1 typ"..., 41) = 41
    stat("/var/empty/sshd", {st_mode=S_IFDIR|0711, st_size=4096, ...}) = 0
    setgroups(0, [])                        = 0
    write(2, "debug1: rexec_argv[0]='/usr/sbin"..., 40) = 40
    write(2, "debug1: rexec_argv[1]='-dddDp'\r\n", 32) = 32
    write(2, "debug1: rexec_argv[2]='19999'\r\n", 31) = 31
    chdir("/")                              = 0
    rt_sigaction(SIGPIPE, NULL, {SIG_DFL, [], 0}, 8) = 0
    rt_sigaction(SIGPIPE, {0x1, [], SA_RESTORER, 0x2b9e534f82f0}, NULL, 8) = 0
    socket(PF_INET, SOCK_STREAM, IPPROTO_TCP) = 3
    fcntl(3, F_GETFL)                       = 0x2 (flags O_RDWR)
    write(2, "debug2: fd 3 setting O_NONBLOCK\r"..., 33) = 33
    fcntl(3, F_SETFL, O_RDWR|O_NONBLOCK)    = 0
    setsockopt(3, SOL_SOCKET, SO_REUSEADDR, [1], 4) = 0
    write(2, "debug1: Bind to port 19999 on 0."..., 40) = 40
    bind(3, {sa_family=AF_INET, sin_port=htons(19999), sin_addr=inet_addr("0.0.0.0")}, 16) = 0
    write(2, "Server listening on 0.0.0.0 port"..., 41) = 41
    listen(3, 128)                          = 0
    socket(PF_INET6, SOCK_STREAM, IPPROTO_TCP) = -1 EAFNOSUPPORT (Address family not supported by protocol)
    write(2, "socket: Address family not suppo"..., 50) = 50
    rt_sigaction(SIGHUP, NULL, {SIG_DFL, [], 0}, 8) = 0
    rt_sigaction(SIGHUP, {0x55555555f7b0, [], SA_RESTORER, 0x2b9e534f82f0}, NULL, 8) = 0
    rt_sigaction(SIGTERM, NULL, {SIG_DFL, [], 0}, 8) = 0
    rt_sigaction(SIGTERM, {0x55555555f430, [], SA_RESTORER, 0x2b9e534f82f0}, NULL, 8) = 0
    rt_sigaction(SIGQUIT, NULL, {SIG_DFL, [], 0}, 8) = 0
    rt_sigaction(SIGQUIT, {0x55555555f430, [], SA_RESTORER, 0x2b9e534f82f0}, NULL, 8) = 0
    rt_sigaction(SIGCHLD, NULL, {SIG_DFL, [], 0}, 8) = 0
    rt_sigaction(SIGCHLD, {0x55555555fc10, [], SA_RESTORER, 0x2b9e534f82f0}, NULL, 8) = 0
    select(4, [3], NULL, NULL, NULL)        = 1 (in [3])
    accept(3, {sa_family=AF_INET, sin_port=htons(56979), sin_addr=inet_addr("127.0.0.1")}, [4294967312]) = 4
    fcntl(4, F_GETFL)                       = 0x2 (flags O_RDWR)
    write(2, "debug3: fd 4 is not O_NONBLOCK\r\n", 32) = 32
    pipe([5, 6])                            = 0
    socketpair(PF_FILE, SOCK_STREAM, 0, [7, 8]) = 0
    write(2, "debug1: Server will not fork whe"..., 62) = 62
    close(3)                                = 0
    close(5)                                = 0
    close(6)                                = 0
    write(2, "debug3: send_rexec_state: enteri"..., 58) = 58
    write(2, "debug3: ssh_msg_send: type 0\r\n", 30) = 30
    write(7, "\0\0\2\26\0", 5)              = 5
    write(7, "\0\0\2\r\n\n\n\n\n\n\n\n\n\n\n\n\n\nProtocol 2\n\n\n\n"..., 533) = 533
    write(2, "debug3: send_rexec_state: done\r\n", 32) = 32
    close(7)                                = 0
    write(2, "debug1: rexec start in 4 out 4 n"..., 57) = 57
    dup2(4, 0)                              = 0
    dup2(0, 1)                              = 1
    close(4)                                = 0
    dup2(8, 5)                              = 5
    close(8)                                = 0
    execve("/usr/sbin/sshd", ["/usr/sbin/sshd", "-dddDp", "19999", "-R"], [/* 25 vars */]) = 0
    brk(0)                                  = 0x5555557c1000
    mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x2b29837de000
    uname({sys="Linux", node="daniel.itforesight.net", ...}) = 0
    access("/etc/ld.so.preload", R_OK)      = -1 ENOENT (No such file or directory)
    open("/etc/ld.so.cache", O_RDONLY)      = 3
    fstat(3, {st_mode=S_IFREG|0644, st_size=47439, ...}) = 0
    mmap(NULL, 47439, PROT_READ, MAP_PRIVATE, 3, 0) = 0x2b29837df000
    close(3)                                = 0
    open("/lib64/libwrap.so.0", O_RDONLY)   = 3
    read(3, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\340-\0\0\0\0\0\0"..., 832) = 832
    fstat(3, {st_mode=S_IFREG|0755, st_size=35072, ...}) = 0
    mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x2b29837eb000
    mmap(NULL, 2132648, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0x2b29839e0000
    mprotect(0x2b29839e8000, 2093056, PROT_NONE) = 0
    mmap(0x2b2983be7000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x7000) = 0x2b2983be7000
    close(3)                                = 0
    open("/lib64/libpam.so.0", O_RDONLY)    = 3
    read(3, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\300$\0\0\0\0\0\0"..., 832) = 832
    fstat(3, {st_mode=S_IFREG|0755, st_size=44472, ...}) = 0
    mmap(NULL, 2140040, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0x2b2983be9000
    mprotect(0x2b2983bf4000, 2093056, PROT_NONE) = 0
    mmap(0x2b2983df3000, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0xa000) = 0x2b2983df3000
    close(3)                                = 0
    open("/lib64/libdl.so.2", O_RDONLY)     = 3
    read(3, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\20\16\0\0\0\0\0\0"..., 832) = 832
    fstat(3, {st_mode=S_IFREG|0755, st_size=20424, ...}) = 0
    mmap(NULL, 2109696, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0x2b2983df4000
    mprotect(0x2b2983df6000, 2097152, PROT_NONE) = 0
    mmap(0x2b2983ff6000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x2000) = 0x2b2983ff6000
    close(3)                                = 0
    open("/lib64/libselinux.so.1", O_RDONLY) = 3
    read(3, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\340E\0\0\0\0\0\0"..., 832) = 832
    fstat(3, {st_mode=S_IFREG|0755, st_size=92960, ...}) = 0
    mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x2b2983ff8000
    mmap(NULL, 2192800, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0x2b2983ff9000
    mprotect(0x2b298400e000, 2097152, PROT_NONE) = 0
    mmap(0x2b298420e000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x15000) = 0x2b298420e000
    mmap(0x2b2984210000, 1440, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_ANONYMOUS, -1, 0) = 0x2b2984210000
    close(3)                                = 0
    open("/lib64/libaudit.so.0", O_RDONLY)  = 3
    read(3, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\340&\0\0\0\0\0\0"..., 832) = 832
    fstat(3, {st_mode=S_IFREG|0755, st_size=96600, ...}) = 0
    mmap(NULL, 2191888, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0x2b2984211000
    mprotect(0x2b2984228000, 2093056, PROT_NONE) = 0
    mmap(0x2b2984427000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x16000) = 0x2b2984427000
    close(3)                                = 0
    open("/usr/lib64/libfipscheck.so.1", O_RDONLY) = 3
    read(3, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\300\n\0\0\0\0\0\0"..., 832) = 832
    fstat(3, {st_mode=S_IFREG|0755, st_size=6680, ...}) = 0
    mmap(NULL, 2102008, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0x2b2984429000
    mprotect(0x2b298442b000, 2093056, PROT_NONE) = 0
    mmap(0x2b298462a000, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x1000) = 0x2b298462a000
    close(3)                                = 0
    open("/lib64/libcrypto.so.6", O_RDONLY) = 3
    read(3, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\300\232\5\0\0\0\0\0"..., 832) = 832
    fstat(3, {st_mode=S_IFREG|0755, st_size=1364912, ...}) = 0
    mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x2b298462b000
    mmap(NULL, 3476304, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0x2b298462c000
    mprotect(0x2b2984759000, 2093056, PROT_NONE) = 0
    mmap(0x2b2984958000, 135168, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x12c000) = 0x2b2984958000
    mmap(0x2b2984979000, 15184, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_ANONYMOUS, -1, 0) = 0x2b2984979000
    close(3)                                = 0
    open("/lib64/libutil.so.1", O_RDONLY)   = 3
    read(3, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\200\16\0\0\0\0\0\0"..., 832) = 832
    fstat(3, {st_mode=S_IFREG|0755, st_size=15280, ...}) = 0
    mmap(NULL, 2105616, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0x2b298497d000
    mprotect(0x2b298497f000, 2093056, PROT_NONE) = 0
    mmap(0x2b2984b7e000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x1000) = 0x2b2984b7e000
    close(3)                                = 0
    open("/lib64/libz.so.1", O_RDONLY)      = 3
    read(3, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\220\36\0\0\0\0\0\0"..., 832) = 832
    fstat(3, {st_mode=S_IFREG|0755, st_size=83280, ...}) = 0
    mmap(NULL, 2178544, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0x2b2984b80000
    mprotect(0x2b2984b94000, 2093056, PROT_NONE) = 0
    mmap(0x2b2984d93000, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x13000) = 0x2b2984d93000
    close(3)                                = 0
    open("/lib64/libnsl.so.1", O_RDONLY)    = 3
    read(3, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\240@\0\0\0\0\0\0"..., 832) = 832
    fstat(3, {st_mode=S_IFREG|0755, st_size=111480, ...}) = 0
    mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x2b2984d94000
    mmap(NULL, 2194096, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0x2b2984d95000
    mprotect(0x2b2984daa000, 2093056, PROT_NONE) = 0
    mmap(0x2b2984fa9000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x14000) = 0x2b2984fa9000
    mmap(0x2b2984fab000, 6832, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_ANONYMOUS, -1, 0) = 0x2b2984fab000
    close(3)                                = 0
    open("/lib64/libcrypt.so.1", O_RDONLY)  = 3
    read(3, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\360\t\0\0\0\0\0\0"..., 832) = 832
    fstat(3, {st_mode=S_IFREG|0755, st_size=45728, ...}) = 0
    mmap(NULL, 2322880, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0x2b2984fad000
    mprotect(0x2b2984fb6000, 2093056, PROT_NONE) = 0
    mmap(0x2b29851b5000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x8000) = 0x2b29851b5000
    mmap(0x2b29851b7000, 184768, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_ANONYMOUS, -1, 0) = 0x2b29851b7000
    close(3)                                = 0
    open("/lib64/libresolv.so.2", O_RDONLY) = 3
    read(3, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\0203\0\0\0\0\0\0"..., 832) = 832
    fstat(3, {st_mode=S_IFREG|0755, st_size=89880, ...}) = 0
    mmap(NULL, 2181896, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0x2b29851e5000
    mprotect(0x2b29851f6000, 2097152, PROT_NONE) = 0
    mmap(0x2b29853f6000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x11000) = 0x2b29853f6000
    mmap(0x2b29853f8000, 6920, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_ANONYMOUS, -1, 0) = 0x2b29853f8000
    close(3)                                = 0
    open("/usr/lib64/libgssapi_krb5.so.2", O_RDONLY) = 3
    read(3, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\0\222\0\0\0\0\0\0"..., 832) = 832
    fstat(3, {st_mode=S_IFREG|0755, st_size=188328, ...}) = 0
    mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x2b29853fa000
    mmap(NULL, 2283888, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0x2b29853fb000
    mprotect(0x2b2985427000, 2097152, PROT_NONE) = 0
    mmap(0x2b2985627000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x2c000) = 0x2b2985627000
    close(3)                                = 0
    open("/usr/lib64/libkrb5.so.3", O_RDONLY) = 3
    read(3, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\320\222\1\0\0\0\0\0"..., 832) = 832
    fstat(3, {st_mode=S_IFREG|0755, st_size=611312, ...}) = 0
    mmap(NULL, 2706656, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0x2b2985629000
    mprotect(0x2b29856ba000, 2097152, PROT_NONE) = 0
    mmap(0x2b29858ba000, 16384, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x91000) = 0x2b29858ba000
    close(3)                                = 0
    open("/usr/lib64/libk5crypto.so.3", O_RDONLY) = 3
    read(3, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\260V\0\0\0\0\0\0"..., 832) = 832
    fstat(3, {st_mode=S_IFREG|0755, st_size=151176, ...}) = 0
    mmap(NULL, 2247528, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0x2b29858be000
    mprotect(0x2b29858e2000, 2093056, PROT_NONE) = 0
    mmap(0x2b2985ae1000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x23000) = 0x2b2985ae1000
    close(3)                                = 0
    open("/lib64/libcom_err.so.2", O_RDONLY) = 3
    read(3, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\320\n\0\0\0\0\0\0"..., 832) = 832
    fstat(3, {st_mode=S_IFREG|0755, st_size=7832, ...}) = 0
    mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x2b2985ae3000
    mmap(NULL, 2103144, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0x2b2985ae4000
    mprotect(0x2b2985ae6000, 2093056, PROT_NONE) = 0
    mmap(0x2b2985ce5000, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x1000) = 0x2b2985ce5000
    close(3)                                = 0
    open("/usr/lib64/libnss3.so", O_RDONLY) = 3
    read(3, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\220\211\1\0\0\0\0\0"..., 832) = 832
    fstat(3, {st_mode=S_IFREG|0755, st_size=1232280, ...}) = 0
    mmap(NULL, 3333416, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0x2b2985ce6000
    mprotect(0x2b2985e0d000, 2093056, PROT_NONE) = 0
    mmap(0x2b298600c000, 28672, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x126000) = 0x2b298600c000
    mmap(0x2b2986013000, 3368, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_ANONYMOUS, -1, 0) = 0x2b2986013000
    close(3)                                = 0
    open("/lib64/libc.so.6", O_RDONLY)      = 3
    read(3, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\220\332\1\0\0\0\0\0"..., 832) = 832
    fstat(3, {st_mode=S_IFREG|0755, st_size=1712648, ...}) = 0
    mmap(NULL, 3498328, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0x2b2986014000
    mprotect(0x2b2986162000, 2093056, PROT_NONE) = 0
    mmap(0x2b2986361000, 20480, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x14d000) = 0x2b2986361000
    mmap(0x2b2986366000, 16728, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_ANONYMOUS, -1, 0) = 0x2b2986366000
    close(3)                                = 0
    open("/lib64/libsepol.so.1", O_RDONLY)  = 3
    read(3, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0@=\0\0\0\0\0\0"..., 832) = 832
    fstat(3, {st_mode=S_IFREG|0755, st_size=245232, ...}) = 0
    mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x2b298636b000
    mmap(NULL, 2383168, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0x2b298636c000
    mprotect(0x2b29863a7000, 2097152, PROT_NONE) = 0
    mmap(0x2b29865a7000, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x3b000) = 0x2b29865a7000
    mmap(0x2b29865a8000, 40256, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_ANONYMOUS, -1, 0) = 0x2b29865a8000
    close(3)                                = 0
    open("/usr/lib64/libkrb5support.so.0", O_RDONLY) = 3
    read(3, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\360\"\0\0\0\0\0\0"..., 832) = 832
    fstat(3, {st_mode=S_IFREG|0755, st_size=33480, ...}) = 0
    mmap(NULL, 2128848, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0x2b29865b2000
    mprotect(0x2b29865ba000, 2093056, PROT_NONE) = 0
    mmap(0x2b29867b9000, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x7000) = 0x2b29867b9000
    close(3)                                = 0
    open("/lib64/libkeyutils.so.1", O_RDONLY) = 3
    read(3, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0` \0\0\0\0\0\0"..., 832) = 832
    fstat(3, {st_mode=S_IFREG|0755, st_size=32256, ...}) = 0
    mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x2b29867ba000
    mmap(NULL, 2140576, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0x2b29867bb000
    mprotect(0x2b29867c2000, 2097152, PROT_NONE) = 0
    mmap(0x2b29869c2000, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x7000) = 0x2b29869c2000
    mmap(0x2b29869c3000, 10656, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_ANONYMOUS, -1, 0) = 0x2b29869c3000
    close(3)                                = 0
    open("/usr/lib64/libnssutil3.so", O_RDONLY) = 3
    read(3, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\240\250\0\0\0\0\0\0"..., 832) = 832
    fstat(3, {st_mode=S_IFREG|0755, st_size=151592, ...}) = 0
    mmap(NULL, 2248256, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0x2b29869c6000
    mprotect(0x2b29869e5000, 2097152, PROT_NONE) = 0
    mmap(0x2b2986be5000, 24576, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x1f000) = 0x2b2986be5000
    close(3)                                = 0
    open("/usr/lib64/libplc4.so", O_RDONLY) = 3
    read(3, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0p\23\0\0\0\0\0\0"..., 832) = 832
    fstat(3, {st_mode=S_IFREG|0755, st_size=15624, ...}) = 0
    mmap(NULL, 2110904, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0x2b2986beb000
    mprotect(0x2b2986bef000, 2093056, PROT_NONE) = 0
    mmap(0x2b2986dee000, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x3000) = 0x2b2986dee000
    close(3)                                = 0
    open("/usr/lib64/libplds4.so", O_RDONLY) = 3
    read(3, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0@\16\0\0\0\0\0\0"..., 832) = 832
    fstat(3, {st_mode=S_IFREG|0755, st_size=11624, ...}) = 0
    mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x2b2986def000
    mmap(NULL, 2106928, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0x2b2986df0000
    mprotect(0x2b2986df3000, 2093056, PROT_NONE) = 0
    mmap(0x2b2986ff2000, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x2000) = 0x2b2986ff2000
    close(3)                                = 0
    open("/usr/lib64/libnspr4.so", O_RDONLY) = 3
    read(3, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\0\320\0\0\0\0\0\0"..., 832) = 832
    fstat(3, {st_mode=S_IFREG|0755, st_size=230808, ...}) = 0
    mmap(NULL, 2336608, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0x2b2986ff3000
    mprotect(0x2b2987029000, 2097152, PROT_NONE) = 0
    mmap(0x2b2987229000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x36000) = 0x2b2987229000
    mmap(0x2b298722b000, 10080, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_ANONYMOUS, -1, 0) = 0x2b298722b000
    close(3)                                = 0
    open("/lib64/libpthread.so.0", O_RDONLY) = 3
    read(3, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\340W\0\0\0\0\0\0"..., 832) = 832
    fstat(3, {st_mode=S_IFREG|0755, st_size=142744, ...}) = 0
    mmap(NULL, 2204528, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0x2b298722e000
    mprotect(0x2b2987244000, 2093056, PROT_NONE) = 0
    mmap(0x2b2987443000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x15000) = 0x2b2987443000
    mmap(0x2b2987445000, 13168, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_ANONYMOUS, -1, 0) = 0x2b2987445000
    close(3)                                = 0
    mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x2b2987449000
    mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x2b298744a000
    mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x2b298744b000
    arch_prctl(ARCH_SET_FS, 0x2b298744b600) = 0
    mprotect(0x2b2987443000, 4096, PROT_READ) = 0
    mprotect(0x2b2986361000, 16384, PROT_READ) = 0
    mprotect(0x2b29853f6000, 4096, PROT_READ) = 0
    mprotect(0x2b29851b5000, 4096, PROT_READ) = 0
    mprotect(0x2b2984fa9000, 4096, PROT_READ) = 0
    mprotect(0x2b2984b7e000, 4096, PROT_READ) = 0
    mprotect(0x2b2983ff6000, 4096, PROT_READ) = 0
    mprotect(0x2b29839de000, 4096, PROT_READ) = 0
    munmap(0x2b29837df000, 47439)           = 0
    set_tid_address(0x2b298744b690)         = 9751
    set_robust_list(0x2b298744b6a0, 0x18)   = 0
    futex(0x7fff272e6aac, FUTEX_WAKE_PRIVATE, 1) = -1 ENOSYS (Function not implemented)
    rt_sigaction(SIGRTMIN, {0x2b29872333c0, [], SA_RESTORER|SA_SIGINFO, 0x2b298723cbe0}, NULL, 8) = 0
    rt_sigaction(SIGRT_1, {0x2b29872332f0, [], SA_RESTORER|SA_RESTART|SA_SIGINFO, 0x2b298723cbe0}, NULL, 8) = 0
    rt_sigprocmask(SIG_UNBLOCK, [RTMIN RT_1], NULL, 8) = 0
    getrlimit(RLIMIT_STACK, {rlim_cur=8192*1024, rlim_max=8192*1024}) = 0
    futex(0x2b2983ff70ec, FUTEX_WAKE, 2147483647) = 0
    brk(0)                                  = 0x5555557c1000
    brk(0x5555557e2000)                     = 0x5555557e2000
    mprotect(0x5555557b6000, 4096, PROT_READ|PROT_WRITE) = 0
    mprotect(0x555555576000, 4096, PROT_READ|PROT_WRITE|PROT_EXEC) = 0
    mprotect(0x555555576000, 4096, PROT_READ|PROT_EXEC) = 0
    mprotect(0x5555557b6000, 4096, PROT_READ|PROT_WRITE) = 0
    mprotect(0x5555557b6000, 4096, PROT_READ|PROT_WRITE) = 0
    mprotect(0x5555557b6000, 4096, PROT_READ|PROT_WRITE) = 0
    mprotect(0x5555557b6000, 4096, PROT_READ|PROT_WRITE) = 0
    mprotect(0x5555557b6000, 4096, PROT_READ|PROT_WRITE) = 0
    mprotect(0x555555560000, 4096, PROT_READ|PROT_WRITE|PROT_EXEC) = 0
    mprotect(0x555555560000, 4096, PROT_READ|PROT_EXEC) = 0
    mprotect(0x555555576000, 4096, PROT_READ|PROT_WRITE|PROT_EXEC) = 0
    mprotect(0x555555576000, 4096, PROT_READ|PROT_EXEC) = 0
    mprotect(0x55555557b000, 4096, PROT_READ|PROT_WRITE|PROT_EXEC) = 0
    mprotect(0x55555557b000, 4096, PROT_READ|PROT_EXEC) = 0
    access("/etc/selinux/", F_OK)           = 0
    open("/etc/selinux/config", O_RDONLY)   = -1 ENOENT (No such file or directory)
    open("/proc/mounts", O_RDONLY)          = 3
    fstat(3, {st_mode=S_IFREG|0444, st_size=0, ...}) = 0
    mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x2b29837df000
    read(3, "rootfs / rootfs rw 0 0\n/dev/root"..., 1024) = 534
    close(3)                                = 0
    munmap(0x2b29837df000, 4096)            = 0
    open("/selinux/mls", O_RDONLY)          = 3
    read(3, "0", 19)                        = 1
    close(3)                                = 0
    open("/proc/sys/crypto/fips_enabled", O_RDONLY) = -1 ENOENT (No such file or directory)
    open("/etc/pki/tls/openssl.cnf", O_RDONLY) = 3
    fstat(3, {st_mode=S_IFREG|0644, st_size=9828, ...}) = 0
    mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x2b29837df000
    read(3, "#\n# OpenSSL example configuratio"..., 4096) = 4096
    read(3, "trings).\n# MASK:XXXX a literal m"..., 4096) = 4096
    read(3, "dentifier=keyid:always,issuer:al"..., 4096) = 1636
    read(3, "", 4096)                       = 0
    close(3)                                = 0
    munmap(0x2b29837df000, 4096)            = 0
    geteuid()                               = 0
    setgroups(0, [])                        = 0
    open("/dev/null", O_RDWR)               = 3
    close(3)                                = 0
    open("/proc/9751/fd", O_RDONLY|O_NONBLOCK|O_DIRECTORY) = 3
    fcntl(3, F_SETFD, FD_CLOEXEC)           = 0
    getdents(3, /* 7 entries */, 32768)     = 168
    getdents(3, /* 0 entries */, 32768)     = 0
    close(3)                                = 0
    time([1356837337])                      = 1356837337
    open("/etc/localtime", O_RDONLY)        = 3
    fstat(3, {st_mode=S_IFREG|0644, st_size=3519, ...}) = 0
    fstat(3, {st_mode=S_IFREG|0644, st_size=3519, ...}) = 0
    mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x2b29837df000
    read(3, "TZif2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\4\0\0\0\4\0\0\0\0"..., 4096) = 3519
    lseek(3, -2252, SEEK_CUR)               = 1267
    read(3, "TZif2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\5\0\0\0\5\0\0\0\0"..., 4096) = 2252
    close(3)                                = 0
    munmap(0x2b29837df000, 4096)            = 0
    stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=3519, ...}) = 0
    stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=3519, ...}) = 0
    stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=3519, ...}) = 0
    socket(PF_FILE, SOCK_DGRAM, 0)          = 3
    fcntl(3, F_SETFD, FD_CLOEXEC)           = 0
    connect(3, {sa_family=AF_FILE, path="/dev/log"...}, 110) = 0
    sendto(3, "<39>Dec 29 22:15:37 sshd[9751]: "..., 73, MSG_NOSIGNAL, NULL, 0) = 73
    close(3)                                = 0
    time([1356837337])                      = 1356837337
    stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=3519, ...}) = 0
    stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=3519, ...}) = 0
    stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=3519, ...}) = 0
    socket(PF_FILE, SOCK_DGRAM, 0)          = 3
    fcntl(3, F_SETFD, FD_CLOEXEC)           = 0
    connect(3, {sa_family=AF_FILE, path="/dev/log"...}, 110) = 0
    sendto(3, "<39>Dec 29 22:15:37 sshd[9751]: "..., 61, MSG_NOSIGNAL, NULL, 0) = 61
    close(3)                                = 0
    read(5, "\0\0\2\26", 4)                 = 4
    read(5, "\0\0\0\2\r\n\n\n\n\n\n\n\n\n\n\n\n\n\nProtocol 2\n\n\n"..., 534) = 534
    time([1356837337])                      = 1356837337
    stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=3519, ...}) = 0
    stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=3519, ...}) = 0
    stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=3519, ...}) = 0
    socket(PF_FILE, SOCK_DGRAM, 0)          = 3
    fcntl(3, F_SETFD, FD_CLOEXEC)           = 0
    connect(3, {sa_family=AF_FILE, path="/dev/log"...}, 110) = 0
    sendto(3, "<39>Dec 29 22:15:37 sshd[9751]: "..., 62, MSG_NOSIGNAL, NULL, 0) = 62
    close(3)                                = 0
    time([1356837337])                      = 1356837337
    stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=3519, ...}) = 0
    stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=3519, ...}) = 0
    stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=3519, ...}) = 0
    socket(PF_FILE, SOCK_DGRAM, 0)          = 3
    fcntl(3, F_SETFD, FD_CLOEXEC)           = 0
    connect(3, {sa_family=AF_FILE, path="/dev/log"...}, 110) = 0
    sendto(3, "<39>Dec 29 22:15:37 sshd[9751]: "..., 81, MSG_NOSIGNAL, NULL, 0) = 81
    close(3)                                = 0
    stat("/dev/urandom", {st_mode=S_IFCHR|0444, st_rdev=makedev(1, 9), ...}) = 0
    open("/dev/urandom", O_RDONLY)          = 3
    read(3, "\344\223;s(\215", 6)           = 6
    close(3)                                = 0
    open("/dev/urandom", O_RDONLY|O_NOCTTY|O_NONBLOCK) = 3
    fstat(3, {st_mode=S_IFCHR|0444, st_rdev=makedev(1, 9), ...}) = 0
    poll([{fd=3, events=POLLIN}], 1, 10)    = 1 ([{fd=3, revents=POLLIN}])
    read(3, "\23:\17Sh\31\354[*u\3\206KPQ\321\372f0,O0\255\203(]\346\36\342G\33\321"..., 48) = 48
    close(3)                                = 0
    getuid()                                = 0
    time(NULL)                              = 1356837337
    open("/etc/gai.conf", O_RDONLY)         = -1 ENOENT (No such file or directory)
    futex(0x2b2986367a08, FUTEX_WAKE, 2147483647) = 0
    socket(PF_NETLINK, SOCK_RAW, 0)         = 3
    bind(3, {sa_family=AF_NETLINK, pid=0, groups=00000000}, 12) = 0
    getsockname(3, {sa_family=AF_NETLINK, pid=9751, groups=00000000}, [2823292353979088908]) = 0
    time(NULL)                              = 1356837337
    sendto(3, "\24\0\0\0\26\0\1\3\331\261\337P\0\0\0\0\0\0\0\0", 20, 0, {sa_family=AF_NETLINK, pid=0, groups=00000000}, 12) = 20
    recvmsg(3, {msg_name(12)={sa_family=AF_NETLINK, pid=0, groups=00000000}, msg_iov(1)=[{"<\0\0\0\24\0\2\0\331\261\337P\27&\0\0\2\10\200\376\1\0\0\0\10\0\1\0\177\0\0\1"..., 4096}], msg_controllen=0, msg_flags=0}, 0) = 332
    recvmsg(3, {msg_name(12)={sa_family=AF_NETLINK, pid=0, groups=00000000}, msg_iov(1)=[{"\24\0\0\0\3\0\2\0\331\261\337P\27&\0\0\0\0\0\0\1\0\0\0\10\0\1\0\177\0\0\1"..., 4096}], msg_controllen=0, msg_flags=0}, 0) = 20
    close(3)                                = 0
    socket(PF_INET6, SOCK_DGRAM, IPPROTO_IP) = -1 EAFNOSUPPORT (Address family not supported by protocol)
    socket(PF_INET, SOCK_DGRAM, IPPROTO_IP) = 3
    connect(3, {sa_family=AF_INET, sin_port=htons(19999), sin_addr=inet_addr("0.0.0.0")}, 16) = 0
    getsockname(3, {sa_family=AF_INET, sin_port=htons(33406), sin_addr=inet_addr("127.0.0.1")}, [8589934608]) = 0
    close(3)                                = 0
    time([1356837337])                      = 1356837337
    stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=3519, ...}) = 0
    stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=3519, ...}) = 0
    stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=3519, ...}) = 0
    socket(PF_FILE, SOCK_DGRAM, 0)          = 3
    fcntl(3, F_SETFD, FD_CLOEXEC)           = 0
    connect(3, {sa_family=AF_FILE, path="/dev/log"...}, 110) = 0
    sendto(3, "<39>Dec 29 22:15:37 sshd[9751]: "..., 66, MSG_NOSIGNAL, NULL, 0) = 66
    close(3)                                = 0
    socket(PF_FILE, SOCK_STREAM, 0)         = 3
    fcntl(3, F_SETFL, O_RDWR|O_NONBLOCK)    = 0
    connect(3, {sa_family=AF_FILE, path="/var/run/nscd/socket"...}, 110) = -1 ENOENT (No such file or directory)
    close(3)                                = 0
    socket(PF_FILE, SOCK_STREAM, 0)         = 3
    fcntl(3, F_SETFL, O_RDWR|O_NONBLOCK)    = 0
    connect(3, {sa_family=AF_FILE, path="/var/run/nscd/socket"...}, 110) = -1 ENOENT (No such file or directory)
    close(3)                                = 0
    open("/etc/nsswitch.conf", O_RDONLY)    = 3
    fstat(3, {st_mode=S_IFREG|0644, st_size=1717, ...}) = 0
    mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x2b29837df000
    read(3, "#\n# /etc/nsswitch.conf\n#\n# An ex"..., 4096) = 1717
    read(3, "", 4096)                       = 0
    close(3)                                = 0
    munmap(0x2b29837df000, 4096)            = 0
    open("/etc/ld.so.cache", O_RDONLY)      = 3
    fstat(3, {st_mode=S_IFREG|0644, st_size=47439, ...}) = 0
    mmap(NULL, 47439, PROT_READ, MAP_PRIVATE, 3, 0) = 0x2b29837df000
    close(3)                                = 0
    open("/lib64/libnss_files.so.2", O_RDONLY) = 3
    read(3, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\340\37\0\0\0\0\0\0"..., 832) = 832
    fstat(3, {st_mode=S_IFREG|0755, st_size=53880, ...}) = 0
    mmap(NULL, 2139432, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0x2b298744c000
    mprotect(0x2b2987456000, 2093056, PROT_NONE) = 0
    mmap(0x2b2987655000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x9000) = 0x2b2987655000
    close(3)                                = 0
    mprotect(0x2b2987655000, 4096, PROT_READ) = 0
    munmap(0x2b29837df000, 47439)           = 0
    open("/etc/passwd", O_RDONLY)           = 3
    fcntl(3, F_GETFD)                       = 0
    fcntl(3, F_SETFD, FD_CLOEXEC)           = 0
    fstat(3, {st_mode=S_IFREG|0644, st_size=3120, ...}) = 0
    mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x2b29837df000
    read(3, "root:x:0:0:root:/root:/bin/bash\n"..., 4096) = 3120
    close(3)                                = 0
    munmap(0x2b29837df000, 4096)            = 0
    open("/etc/ssh/ssh_host_rsa_key", O_RDONLY) = 3
    fstat(3, {st_mode=S_IFREG|0600, st_size=1675, ...}) = 0
    getuid()                                = 0
    fstat(3, {st_mode=S_IFREG|0600, st_size=1675, ...}) = 0
    read(3, "-----BEGIN RSA PRIVATE KEY-----\n"..., 1675) = 1675
    time([1356837337])                      = 1356837337
    stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=3519, ...}) = 0
    stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=3519, ...}) = 0
    stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=3519, ...}) = 0
    socket(PF_FILE, SOCK_DGRAM, 0)          = 4
    fcntl(4, F_SETFD, FD_CLOEXEC)           = 0
    connect(4, {sa_family=AF_FILE, path="/dev/log"...}, 110) = 0
    sendto(4, "<39>Dec 29 22:15:37 sshd[9751]: "..., 86, MSG_NOSIGNAL, NULL, 0) = 86
    close(4)                                = 0
    lseek(3, 0, SEEK_SET)                   = 0
    fcntl(3, F_GETFL)                       = 0x8000 (flags O_RDONLY|O_LARGEFILE)
    fstat(3, {st_mode=S_IFREG|0600, st_size=1675, ...}) = 0
    mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x2b29837df000
    lseek(3, 0, SEEK_CUR)                   = 0
    read(3, "-----BEGIN RSA PRIVATE KEY-----\n"..., 4096) = 1675
    time([1356837337])                      = 1356837337
    close(3)                                = 0
    munmap(0x2b29837df000, 4096)            = 0
    time([1356837337])                      = 1356837337
    stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=3519, ...}) = 0
    stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=3519, ...}) = 0
    stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=3519, ...}) = 0
    socket(PF_FILE, SOCK_DGRAM, 0)          = 3
    fcntl(3, F_SETFD, FD_CLOEXEC)           = 0
    connect(3, {sa_family=AF_FILE, path="/dev/log"...}, 110) = 0
    sendto(3, "<39>Dec 29 22:15:37 sshd[9751]: "..., 75, MSG_NOSIGNAL, NULL, 0) = 75
    close(3)                                = 0
    time([1356837337])                      = 1356837337
    stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=3519, ...}) = 0
    stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=3519, ...}) = 0
    stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=3519, ...}) = 0
    socket(PF_FILE, SOCK_DGRAM, 0)          = 3
    fcntl(3, F_SETFD, FD_CLOEXEC)           = 0
    connect(3, {sa_family=AF_FILE, path="/dev/log"...}, 110) = 0
    sendto(3, "<39>Dec 29 22:15:37 sshd[9751]: "..., 71, MSG_NOSIGNAL, NULL, 0) = 71
    close(3)                                = 0
    open("/etc/ssh/ssh_host_dsa_key", O_RDONLY) = 3
    fstat(3, {st_mode=S_IFREG|0600, st_size=668, ...}) = 0
    getuid()                                = 0
    fstat(3, {st_mode=S_IFREG|0600, st_size=668, ...}) = 0
    read(3, "-----BEGIN DSA PRIVATE KEY-----\n"..., 668) = 668
    time([1356837337])                      = 1356837337
    stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=3519, ...}) = 0
    stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=3519, ...}) = 0
    stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=3519, ...}) = 0
    socket(PF_FILE, SOCK_DGRAM, 0)          = 4
    fcntl(4, F_SETFD, FD_CLOEXEC)           = 0
    connect(4, {sa_family=AF_FILE, path="/dev/log"...}, 110) = 0
    sendto(4, "<39>Dec 29 22:15:37 sshd[9751]: "..., 86, MSG_NOSIGNAL, NULL, 0) = 86
    close(4)                                = 0
    lseek(3, 0, SEEK_SET)                   = 0
    fcntl(3, F_GETFL)                       = 0x8000 (flags O_RDONLY|O_LARGEFILE)
    fstat(3, {st_mode=S_IFREG|0600, st_size=668, ...}) = 0
    mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x2b29837df000
    lseek(3, 0, SEEK_CUR)                   = 0
    read(3, "-----BEGIN DSA PRIVATE KEY-----\n"..., 4096) = 668
    close(3)                                = 0
    munmap(0x2b29837df000, 4096)            = 0
    time([1356837337])                      = 1356837337
    stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=3519, ...}) = 0
    stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=3519, ...}) = 0
    stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=3519, ...}) = 0
    socket(PF_FILE, SOCK_DGRAM, 0)          = 3
    fcntl(3, F_SETFD, FD_CLOEXEC)           = 0
    connect(3, {sa_family=AF_FILE, path="/dev/log"...}, 110) = 0
    sendto(3, "<39>Dec 29 22:15:37 sshd[9751]: "..., 75, MSG_NOSIGNAL, NULL, 0) = 75
    close(3)                                = 0
    time([1356837337])                      = 1356837337
    stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=3519, ...}) = 0
    stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=3519, ...}) = 0
    stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=3519, ...}) = 0
    socket(PF_FILE, SOCK_DGRAM, 0)          = 3
    fcntl(3, F_SETFD, FD_CLOEXEC)           = 0
    connect(3, {sa_family=AF_FILE, path="/dev/log"...}, 110) = 0
    sendto(3, "<39>Dec 29 22:15:37 sshd[9751]: "..., 71, MSG_NOSIGNAL, NULL, 0) = 71
    close(3)                                = 0
    stat("/var/empty/sshd", {st_mode=S_IFDIR|0711, st_size=4096, ...}) = 0
    setgroups(0, [])                        = 0
    chdir("/")                              = 0
    rt_sigaction(SIGPIPE, NULL, {0x1, [], 0}, 8) = 0
    close(5)                                = 0
    dup(0)                                  = 3
    open("/dev/null", O_RDWR)               = 4
    dup2(4, 0)                              = 0
    dup2(4, 1)                              = 1
    close(4)                                = 0
    write(2, "debug1: inetd sockets after dupp"..., 43) = 43
    fcntl(3, F_SETFD, FD_CLOEXEC)           = 0
    fcntl(3, F_SETFD, FD_CLOEXEC)           = 0
    alarm(0)                                = 0
    rt_sigaction(SIGALRM, NULL, {SIG_DFL, [], 0}, 8) = 0
    rt_sigaction(SIGHUP, NULL, {SIG_DFL, [], 0}, 8) = 0
    rt_sigaction(SIGTERM, NULL, {SIG_DFL, [], 0}, 8) = 0
    rt_sigaction(SIGQUIT, NULL, {SIG_DFL, [], 0}, 8) = 0
    rt_sigaction(SIGCHLD, NULL, {SIG_DFL, [], 0}, 8) = 0
    rt_sigaction(SIGINT, NULL, {SIG_DFL, [], 0}, 8) = 0
    setsockopt(3, SOL_SOCKET, SO_KEEPALIVE, [1], 4) = 0
    getpeername(3, {sa_family=AF_INET, sin_port=htons(56979), sin_addr=inet_addr("127.0.0.1")}, [10654953776995106832]) = 0
    getpeername(3, {sa_family=AF_INET, sin_port=htons(56979), sin_addr=inet_addr("127.0.0.1")}, [7218796222969020432]) = 0
    open("/etc/protocols", O_RDONLY)        = 4
    fcntl(4, F_GETFD)                       = 0
    fcntl(4, F_SETFD, FD_CLOEXEC)           = 0
    fstat(4, {st_mode=S_IFREG|0644, st_size=6108, ...}) = 0
    mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x2b29837df000
    read(4, "# /etc/protocols:\n# $Id: protoco"..., 4096) = 4096
    close(4)                                = 0
    munmap(0x2b29837df000, 4096)            = 0
    getsockopt(3, SOL_IP, IP_OPTIONS, "", [0]) = 0
    getpeername(3, {sa_family=AF_INET, sin_port=htons(56979), sin_addr=inet_addr("127.0.0.1")}, [16]) = 0
    getsockname(3, {sa_family=AF_INET, sin_port=htons(19999), sin_addr=inet_addr("127.0.0.1")}, [16]) = 0
    getsockname(3, {sa_family=AF_INET, sin_port=htons(19999), sin_addr=inet_addr("127.0.0.1")}, [2823292525777780752]) = 0
    getpeername(3, {sa_family=AF_INET, sin_port=htons(56979), sin_addr=inet_addr("127.0.0.1")}, [2823292525777780752]) = 0
    open("/etc/hosts.allow", O_RDONLY)      = 4
    fstat(4, {st_mode=S_IFREG|0644, st_size=161, ...}) = 0
    mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x2b29837df000
    read(4, "#\n# hosts.allow\tThis file descri"..., 4096) = 161
    read(4, "", 4096)                       = 0
    close(4)                                = 0
    munmap(0x2b29837df000, 4096)            = 0
    open("/etc/hosts.deny", O_RDONLY)       = 4
    fstat(4, {st_mode=S_IFREG|0644, st_size=165, ...}) = 0
    mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x2b29837df000
    read(4, "#\n# hosts.deny\tThis file describ"..., 4096) = 165
    read(4, "", 4096)                       = 0
    close(4)                                = 0
    munmap(0x2b29837df000, 4096)            = 0
    write(2, "Connection from 127.0.0.1 port 5"..., 38) = 38
    rt_sigaction(SIGALRM, NULL, {SIG_DFL, [], 0}, 8) = 0
    rt_sigaction(SIGALRM, {0x55555555fc70, [], SA_RESTORER|SA_INTERRUPT, 0x2b29860442f0}, NULL, 8) = 0
    write(3, "SSH-2.0-OpenSSH_4.3\n", 20)   = 20
    read(3, "S", 1)                         = 1
    read(3, "S", 1)                         = 1
    read(3, "H", 1)                         = 1
    read(3, "-", 1)                         = 1
    read(3, "2", 1)                         = 1
    read(3, ".", 1)                         = 1
    read(3, "0", 1)                         = 1
    read(3, "-", 1)                         = 1
    read(3, "O", 1)                         = 1
    read(3, "p", 1)                         = 1
    read(3, "e", 1)                         = 1
    read(3, "n", 1)                         = 1
    read(3, "S", 1)                         = 1
    read(3, "S", 1)                         = 1
    read(3, "H", 1)                         = 1
    read(3, "_", 1)                         = 1
    read(3, "4", 1)                         = 1
    read(3, ".", 1)                         = 1
    read(3, "3", 1)                         = 1
    read(3, "\n", 1)                        = 1
    --- SIGSEGV (Segmentation fault) @ 0 (0) ---
    +++ killed by SIGSEGV (core dumped) +++
    # ldd /usr/bin/ssh
    Code:
            libfipscheck.so.1 => /usr/lib64/libfipscheck.so.1 (0x00002acfa6eeb000)
            libcrypto.so.6 => /lib64/libcrypto.so.6 (0x00002acfa70ed000)
            libutil.so.1 => /lib64/libutil.so.1 (0x00002acfa743e000)
            libz.so.1 => /lib64/libz.so.1 (0x00002acfa7642000)
            libnsl.so.1 => /lib64/libnsl.so.1 (0x00002acfa7856000)
            libcrypt.so.1 => /lib64/libcrypt.so.1 (0x00002acfa7a6e000)
            libresolv.so.2 => /lib64/libresolv.so.2 (0x00002acfa7ca7000)
            libgssapi_krb5.so.2 => /usr/lib64/libgssapi_krb5.so.2 (0x00002acfa7ebc000)
            libkrb5.so.3 => /usr/lib64/libkrb5.so.3 (0x00002acfa80ea000)
            libk5crypto.so.3 => /usr/lib64/libk5crypto.so.3 (0x00002acfa8380000)
            libcom_err.so.2 => /lib64/libcom_err.so.2 (0x00002acfa85a5000)
            libnss3.so => /usr/lib64/libnss3.so (0x00002acfa87a7000)
            libc.so.6 => /lib64/libc.so.6 (0x00002acfa8ad6000)
            libplc4.so => /usr/lib64/libplc4.so (0x00002acfa8e2d000)
            libdl.so.2 => /lib64/libdl.so.2 (0x00002acfa9031000)
            libkrb5support.so.0 => /usr/lib64/libkrb5support.so.0 (0x00002acfa9236000)
            libkeyutils.so.1 => /lib64/libkeyutils.so.1 (0x00002acfa943e000)
            libnssutil3.so => /usr/lib64/libnssutil3.so (0x00002acfa9649000)
            libplds4.so => /usr/lib64/libplds4.so (0x00002acfa986f000)
            libnspr4.so => /usr/lib64/libnspr4.so (0x00002acfa9a72000)
            libpthread.so.0 => /lib64/libpthread.so.0 (0x00002acfa9cad000)
            /lib64/ld-linux-x86-64.so.2 (0x0000555555554000)
            libselinux.so.1 => /lib64/libselinux.so.1 (0x00002acfa9ec9000)
            libsepol.so.1 => /lib64/libsepol.so.1 (0x00002acfaa0e1000)
    # ldd /usr/sbin/sshd
    Code:
            libwrap.so.0 => /lib64/libwrap.so.0 (0x00002b5238dea000)
            libpam.so.0 => /lib64/libpam.so.0 (0x00002b5238ff3000)
            libdl.so.2 => /lib64/libdl.so.2 (0x00002b52391fe000)
            libselinux.so.1 => /lib64/libselinux.so.1 (0x00002b5239403000)
            libaudit.so.0 => /lib64/libaudit.so.0 (0x00002b523961b000)
            libfipscheck.so.1 => /usr/lib64/libfipscheck.so.1 (0x00002b5239833000)
            libcrypto.so.6 => /lib64/libcrypto.so.6 (0x00002b5239a36000)
            libutil.so.1 => /lib64/libutil.so.1 (0x00002b5239d87000)
            libz.so.1 => /lib64/libz.so.1 (0x00002b5239f8a000)
            libnsl.so.1 => /lib64/libnsl.so.1 (0x00002b523a19f000)
            libcrypt.so.1 => /lib64/libcrypt.so.1 (0x00002b523a3b7000)
            libresolv.so.2 => /lib64/libresolv.so.2 (0x00002b523a5ef000)
            libgssapi_krb5.so.2 => /usr/lib64/libgssapi_krb5.so.2 (0x00002b523a805000)
            libkrb5.so.3 => /usr/lib64/libkrb5.so.3 (0x00002b523aa33000)
            libk5crypto.so.3 => /usr/lib64/libk5crypto.so.3 (0x00002b523acc8000)
            libcom_err.so.2 => /lib64/libcom_err.so.2 (0x00002b523aeee000)
            libnss3.so => /usr/lib64/libnss3.so (0x00002b523b0f0000)
            libc.so.6 => /lib64/libc.so.6 (0x00002b523b41e000)
            /lib64/ld-linux-x86-64.so.2 (0x0000555555554000)
            libsepol.so.1 => /lib64/libsepol.so.1 (0x00002b523b776000)
            libkrb5support.so.0 => /usr/lib64/libkrb5support.so.0 (0x00002b523b9bc000)
            libkeyutils.so.1 => /lib64/libkeyutils.so.1 (0x00002b523bbc5000)
            libnssutil3.so => /usr/lib64/libnssutil3.so (0x00002b523bdd0000)
            libplc4.so => /usr/lib64/libplc4.so (0x00002b523bff5000)
            libplds4.so => /usr/lib64/libplds4.so (0x00002b523c1fa000)
            libnspr4.so => /usr/lib64/libnspr4.so (0x00002b523c3fd000)
            libpthread.so.0 => /lib64/libpthread.so.0 (0x00002b523c638000)
     
    #11 Phylum, Dec 29, 2012
    Last edited: Dec 29, 2012
  12. Phylum

    Phylum Active Member

    Joined:
    Apr 20, 2010
    Messages:
    29
    Likes Received:
    0
    Trophy Points:
    1
    Re: cannot ssh into server sshd is up per status everything else works fine

    Since pretty much the last thing it does is open and read /etc/hosts.deny, I checked to make sure I dd not have anything strange in either file:
    Both files are empty
    Code:
    # cat /etc/hosts.*
    #
    # hosts.allow   This file describes the names of the hosts which are
    #               allowed to use the local INET services, as decided
    #               by the '/usr/sbin/tcpd' server.
    #
    
    #
    # hosts.deny    This file describes the names of the hosts which are
    #               *not* allowed to use the local INET services, as decided
    #               by the '/usr/sbin/tcpd' server.
    #

    I renamed them & `touch`d them to recreate - still segfaults.
     
  13. Phylum

    Phylum Active Member

    Joined:
    Apr 20, 2010
    Messages:
    29
    Likes Received:
    0
    Trophy Points:
    1
    Re: cannot ssh into server sshd is up per status everything else works fine

    Just in case this is helpful

    iptables-save
    Code:
    # Generated by iptables-save v1.3.5 on Wed Jan  2 16:23:12 2013
    *mangle
    :PREROUTING ACCEPT [13036683:13716519049]
    :INPUT ACCEPT [13036683:13716519049]
    :FORWARD ACCEPT [0:0]
    :OUTPUT ACCEPT [6529586:6970706256]
    :POSTROUTING ACCEPT [6529426:6970641935]
    COMMIT
    # Completed on Wed Jan  2 16:23:12 2013
    # Generated by iptables-save v1.3.5 on Wed Jan  2 16:23:12 2013
    *nat
    :PREROUTING ACCEPT [143609:9485313]
    :POSTROUTING ACCEPT [35617:2199014]
    :OUTPUT ACCEPT [35661:2248731]
    COMMIT
    # Completed on Wed Jan  2 16:23:12 2013
    # Generated by iptables-save v1.3.5 on Wed Jan  2 16:23:12 2013
    *filter
    :INPUT DROP [0:0]
    :FORWARD DROP [0:0]
    :OUTPUT DROP [0:0]
    :INVALID - [0:0]
    :INVDROP - [0:0]
    :LOCALINPUT - [0:0]
    :LOCALOUTPUT - [0:0]
    :LOGDROPIN - [0:0]
    :LOGDROPOUT - [0:0]
    :acctboth - [0:0]
    -A INPUT -j acctboth
    -A INPUT -s 8.8.4.4 -i ! lo -p tcp -m tcp --dport 53 -j ACCEPT
    -A INPUT -s 8.8.4.4 -i ! lo -p udp -m udp --dport 53 -j ACCEPT
    -A INPUT -s 8.8.4.4 -i ! lo -p tcp -m tcp --sport 53 -j ACCEPT
    -A INPUT -s 8.8.4.4 -i ! lo -p udp -m udp --sport 53 -j ACCEPT
    -A INPUT -s 8.8.8.8 -i ! lo -p tcp -m tcp --dport 53 -j ACCEPT
    -A INPUT -s 8.8.8.8 -i ! lo -p udp -m udp --dport 53 -j ACCEPT
    -A INPUT -s 8.8.8.8 -i ! lo -p tcp -m tcp --sport 53 -j ACCEPT
    -A INPUT -s 8.8.8.8 -i ! lo -p udp -m udp --sport 53 -j ACCEPT
    -A INPUT -i ! lo -j LOCALINPUT
    -A INPUT -i lo -j ACCEPT
    -A INPUT -i ! lo -p tcp -j INVALID
    -A INPUT -i ! lo -m state --state RELATED,ESTABLISHED -j ACCEPT
    -A INPUT -i ! lo -p tcp -m state --state NEW -m tcp --dport 20 -j ACCEPT
    -A INPUT -i ! lo -p tcp -m state --state NEW -m tcp --dport 21 -j ACCEPT
    -A INPUT -i ! lo -p tcp -m state --state NEW -m tcp --dport 22 -j ACCEPT
    -A INPUT -i ! lo -p tcp -m state --state NEW -m tcp --dport 25 -j ACCEPT
    -A INPUT -i ! lo -p tcp -m state --state NEW -m tcp --dport 53 -j ACCEPT
    -A INPUT -i ! lo -p tcp -m state --state NEW -m tcp --dport 80 -j ACCEPT
    -A INPUT -i ! lo -p tcp -m state --state NEW -m tcp --dport 110 -j ACCEPT
    -A INPUT -i ! lo -p tcp -m state --state NEW -m tcp --dport 143 -j ACCEPT
    -A INPUT -i ! lo -p tcp -m state --state NEW -m tcp --dport 443 -j ACCEPT
    -A INPUT -i ! lo -p tcp -m state --state NEW -m tcp --dport 465 -j ACCEPT
    -A INPUT -i ! lo -p tcp -m state --state NEW -m tcp --dport 587 -j ACCEPT
    -A INPUT -i ! lo -p tcp -m state --state NEW -m tcp --dport 993 -j ACCEPT
    -A INPUT -i ! lo -p tcp -m state --state NEW -m tcp --dport 995 -j ACCEPT
    -A INPUT -i ! lo -p tcp -m state --state NEW -m tcp --dport 2077 -j ACCEPT
    -A INPUT -i ! lo -p tcp -m state --state NEW -m tcp --dport 2078 -j ACCEPT
    -A INPUT -i ! lo -p tcp -m state --state NEW -m tcp --dport 2082 -j ACCEPT
    -A INPUT -i ! lo -p tcp -m state --state NEW -m tcp --dport 2083 -j ACCEPT
    -A INPUT -i ! lo -p tcp -m state --state NEW -m tcp --dport 2086 -j ACCEPT
    -A INPUT -i ! lo -p tcp -m state --state NEW -m tcp --dport 2087 -j ACCEPT
    -A INPUT -i ! lo -p tcp -m state --state NEW -m tcp --dport 2095 -j ACCEPT
    -A INPUT -i ! lo -p tcp -m state --state NEW -m tcp --dport 2096 -j ACCEPT
    -A INPUT -i ! lo -p udp -m state --state NEW -m udp --dport 20 -j ACCEPT
    -A INPUT -i ! lo -p udp -m state --state NEW -m udp --dport 21 -j ACCEPT
    -A INPUT -i ! lo -p udp -m state --state NEW -m udp --dport 53 -j ACCEPT
    -A INPUT -i ! lo -p icmp -m icmp --icmp-type 8 -m limit --limit 1/sec -j ACCEPT
    -A INPUT -i ! lo -p icmp -m icmp --icmp-type 0 -m limit --limit 1/sec -j ACCEPT
    -A INPUT -i ! lo -p icmp -m icmp --icmp-type 11 -j ACCEPT
    -A INPUT -i ! lo -p icmp -m icmp --icmp-type 3 -j ACCEPT
    -A INPUT -i ! lo -j LOGDROPIN
    -A OUTPUT -j acctboth
    -A OUTPUT -d 8.8.4.4 -o ! lo -p tcp -m tcp --dport 53 -j ACCEPT
    -A OUTPUT -d 8.8.4.4 -o ! lo -p udp -m udp --dport 53 -j ACCEPT
    -A OUTPUT -d 8.8.4.4 -o ! lo -p tcp -m tcp --sport 53 -j ACCEPT
    -A OUTPUT -d 8.8.4.4 -o ! lo -p udp -m udp --sport 53 -j ACCEPT
    -A OUTPUT -d 8.8.8.8 -o ! lo -p tcp -m tcp --dport 53 -j ACCEPT
    -A OUTPUT -d 8.8.8.8 -o ! lo -p udp -m udp --dport 53 -j ACCEPT
    -A OUTPUT -d 8.8.8.8 -o ! lo -p tcp -m tcp --sport 53 -j ACCEPT
    -A OUTPUT -d 8.8.8.8 -o ! lo -p udp -m udp --sport 53 -j ACCEPT
    -A OUTPUT -o ! lo -j LOCALOUTPUT
    -A OUTPUT -o ! lo -p tcp -m tcp --dport 53 -j ACCEPT
    -A OUTPUT -o ! lo -p udp -m udp --dport 53 -j ACCEPT
    -A OUTPUT -o ! lo -p tcp -m tcp --sport 53 -j ACCEPT
    -A OUTPUT -o ! lo -p udp -m udp --sport 53 -j ACCEPT
    -A OUTPUT -o lo -j ACCEPT
    -A OUTPUT -o ! lo -p tcp -j INVALID
    -A OUTPUT -o ! lo -m state --state RELATED,ESTABLISHED -j ACCEPT
    -A OUTPUT -o ! lo -p tcp -m state --state NEW -m tcp --dport 20 -j ACCEPT
    -A OUTPUT -o ! lo -p tcp -m state --state NEW -m tcp --dport 21 -j ACCEPT
    -A OUTPUT -o ! lo -p tcp -m state --state NEW -m tcp --dport 22 -j ACCEPT
    -A OUTPUT -o ! lo -p tcp -m state --state NEW -m tcp --dport 25 -j ACCEPT
    -A OUTPUT -o ! lo -p tcp -m state --state NEW -m tcp --dport 37 -j ACCEPT
    -A OUTPUT -o ! lo -p tcp -m state --state NEW -m tcp --dport 43 -j ACCEPT
    -A OUTPUT -o ! lo -p tcp -m state --state NEW -m tcp --dport 53 -j ACCEPT
    -A OUTPUT -o ! lo -p tcp -m state --state NEW -m tcp --dport 80 -j ACCEPT
    -A OUTPUT -o ! lo -p tcp -m state --state NEW -m tcp --dport 110 -j ACCEPT
    -A OUTPUT -o ! lo -p tcp -m state --state NEW -m tcp --dport 113 -j ACCEPT
    -A OUTPUT -o ! lo -p tcp -m state --state NEW -m tcp --dport 443 -j ACCEPT
    -A OUTPUT -o ! lo -p tcp -m state --state NEW -m tcp --dport 587 -j ACCEPT
    -A OUTPUT -o ! lo -p tcp -m state --state NEW -m tcp --dport 873 -j ACCEPT
    -A OUTPUT -o ! lo -p tcp -m state --state NEW -m tcp --dport 2087 -j ACCEPT
    -A OUTPUT -o ! lo -p tcp -m state --state NEW -m tcp --dport 2089 -j ACCEPT
    -A OUTPUT -o ! lo -p tcp -m state --state NEW -m tcp --dport 2703 -j ACCEPT
    -A OUTPUT -o ! lo -p udp -m state --state NEW -m udp --dport 20 -j ACCEPT
    -A OUTPUT -o ! lo -p udp -m state --state NEW -m udp --dport 21 -j ACCEPT
    -A OUTPUT -o ! lo -p udp -m state --state NEW -m udp --dport 53 -j ACCEPT
    -A OUTPUT -o ! lo -p udp -m state --state NEW -m udp --dport 113 -j ACCEPT
    -A OUTPUT -o ! lo -p udp -m state --state NEW -m udp --dport 123 -j ACCEPT
    -A OUTPUT -o ! lo -p udp -m state --state NEW -m udp --dport 873 -j ACCEPT
    -A OUTPUT -o ! lo -p udp -m state --state NEW -m udp --dport 6277 -j ACCEPT
    -A OUTPUT -o ! lo -p icmp -m icmp --icmp-type 0 -j ACCEPT
    -A OUTPUT -o ! lo -p icmp -m icmp --icmp-type 8 -j ACCEPT
    -A OUTPUT -o ! lo -p icmp -m icmp --icmp-type 11 -j ACCEPT
    -A OUTPUT -o ! lo -p icmp -m icmp --icmp-type 3 -j ACCEPT
    -A OUTPUT -o ! lo -j LOGDROPOUT
    -A INVALID -m state --state INVALID -j INVDROP
    -A INVALID -p tcp -m tcp --tcp-flags FIN,SYN,RST,PSH,ACK,URG NONE -j INVDROP
    -A INVALID -p tcp -m tcp --tcp-flags FIN,SYN,RST,PSH,ACK,URG FIN,SYN,RST,PSH,ACK,URG -j INVDROP
    -A INVALID -p tcp -m tcp --tcp-flags FIN,SYN FIN,SYN -j INVDROP
    -A INVALID -p tcp -m tcp --tcp-flags SYN,RST SYN,RST -j INVDROP
    -A INVALID -p tcp -m tcp --tcp-flags FIN,RST FIN,RST -j INVDROP
    -A INVALID -p tcp -m tcp --tcp-flags FIN,ACK FIN -j INVDROP
    -A INVALID -p tcp -m tcp --tcp-flags PSH,ACK PSH -j INVDROP
    -A INVALID -p tcp -m tcp --tcp-flags ACK,URG URG -j INVDROP
    -A INVALID -p tcp -m tcp ! --tcp-flags FIN,SYN,RST,ACK SYN -m state --state NEW -j INVDROP
    -A INVDROP -j DROP
    -A LOCALINPUT -s 10.0.0.120 -i ! lo -j ACCEPT
    -A LOCALINPUT -s 10.0.0.74 -i ! lo -j ACCEPT
    -A LOCALINPUT -s 173.79.162.182 -i ! lo -j ACCEPT
    -A LOCALINPUT -s 173.79.175.50 -i ! lo -j ACCEPT
    -A LOCALINPUT -s 58.221.42.178 -i ! lo -j DROP
    -A LOCALINPUT -s 203.45.134.40 -i ! lo -j DROP
    -A LOCALINPUT -s 90.184.114.13 -i ! lo -j DROP
    -A LOCALINPUT -s 23.25.216.129 -i ! lo -j DROP
    -A LOCALINPUT -s 50.34.240.12 -i ! lo -j DROP
    -A LOCALINPUT -s 184.91.103.84 -i ! lo -j DROP
    -A LOCALINPUT -s 74.164.14.171 -i ! lo -j DROP
    -A LOCALINPUT -s 87.216.171.74 -i ! lo -j DROP
    -A LOCALINPUT -s 89.119.220.57 -i ! lo -j DROP
    -A LOCALINPUT -s 173.200.3.25 -i ! lo -j DROP
    -A LOCALINPUT -s 24.96.212.163 -i ! lo -j DROP
    -A LOCALINPUT -s 70.90.65.253 -i ! lo -j DROP
    -A LOCALINPUT -s 50.73.168.197 -i ! lo -j DROP
    -A LOCALINPUT -s 75.149.2.246 -i ! lo -j DROP
    -A LOCALINPUT -s 208.53.75.36 -i ! lo -j DROP
    -A LOCALINPUT -s 71.186.195.38 -i ! lo -j DROP
    -A LOCALINPUT -s 79.189.206.122 -i ! lo -j DROP
    -A LOCALINPUT -s 50.121.152.110 -i ! lo -j DROP
    -A LOCALINPUT -s 24.39.118.70 -i ! lo -j DROP
    -A LOCALINPUT -s 74.11.126.243 -i ! lo -j DROP
    -A LOCALINPUT -s 108.64.133.67 -i ! lo -j DROP
    -A LOCALINPUT -s 37.209.31.239 -i ! lo -j DROP
    -A LOCALINPUT -s 165.228.246.237 -i ! lo -j DROP
    -A LOCALINPUT -s 71.177.221.87 -i ! lo -j DROP
    -A LOCALINPUT -s 70.91.112.89 -i ! lo -j DROP
    -A LOCALINPUT -s 50.194.23.90 -i ! lo -j DROP
    -A LOCALINPUT -s 24.234.155.80 -i ! lo -j DROP
    -A LOCALOUTPUT -d 10.0.0.120 -o ! lo -j ACCEPT
    -A LOCALOUTPUT -d 10.0.0.74 -o ! lo -j ACCEPT
    -A LOCALOUTPUT -d 173.79.162.182 -o ! lo -j ACCEPT
    -A LOCALOUTPUT -d 173.79.175.50 -o ! lo -j ACCEPT
    -A LOCALOUTPUT -d 58.221.42.178 -o ! lo -j DROP
    -A LOCALOUTPUT -d 203.45.134.40 -o ! lo -j DROP
    -A LOCALOUTPUT -d 90.184.114.13 -o ! lo -j DROP
    -A LOCALOUTPUT -d 23.25.216.129 -o ! lo -j DROP
    -A LOCALOUTPUT -d 50.34.240.12 -o ! lo -j DROP
    -A LOCALOUTPUT -d 184.91.103.84 -o ! lo -j DROP
    -A LOCALOUTPUT -d 74.164.14.171 -o ! lo -j DROP
    -A LOCALOUTPUT -d 87.216.171.74 -o ! lo -j DROP
    -A LOCALOUTPUT -d 89.119.220.57 -o ! lo -j DROP
    -A LOCALOUTPUT -d 173.200.3.25 -o ! lo -j DROP
    -A LOCALOUTPUT -d 24.96.212.163 -o ! lo -j DROP
    -A LOCALOUTPUT -d 70.90.65.253 -o ! lo -j DROP
    -A LOCALOUTPUT -d 50.73.168.197 -o ! lo -j DROP
    -A LOCALOUTPUT -d 75.149.2.246 -o ! lo -j DROP
    -A LOCALOUTPUT -d 208.53.75.36 -o ! lo -j DROP
    -A LOCALOUTPUT -d 71.186.195.38 -o ! lo -j DROP
    -A LOCALOUTPUT -d 79.189.206.122 -o ! lo -j DROP
    -A LOCALOUTPUT -d 50.121.152.110 -o ! lo -j DROP
    -A LOCALOUTPUT -d 24.39.118.70 -o ! lo -j DROP
    -A LOCALOUTPUT -d 74.11.126.243 -o ! lo -j DROP
    -A LOCALOUTPUT -d 108.64.133.67 -o ! lo -j DROP
    -A LOCALOUTPUT -d 37.209.31.239 -o ! lo -j DROP
    -A LOCALOUTPUT -d 165.228.246.237 -o ! lo -j DROP
    -A LOCALOUTPUT -d 71.177.221.87 -o ! lo -j DROP
    -A LOCALOUTPUT -d 70.91.112.89 -o ! lo -j DROP
    -A LOCALOUTPUT -d 50.194.23.90 -o ! lo -j DROP
    -A LOCALOUTPUT -d 24.234.155.80 -o ! lo -j DROP
    -A LOGDROPIN -p tcp -m tcp --dport 67 -j DROP
    -A LOGDROPIN -p udp -m udp --dport 67 -j DROP
    -A LOGDROPIN -p tcp -m tcp --dport 68 -j DROP
    -A LOGDROPIN -p udp -m udp --dport 68 -j DROP
    -A LOGDROPIN -p tcp -m tcp --dport 111 -j DROP
    -A LOGDROPIN -p udp -m udp --dport 111 -j DROP
    -A LOGDROPIN -p tcp -m tcp --dport 113 -j DROP
    -A LOGDROPIN -p udp -m udp --dport 113 -j DROP
    -A LOGDROPIN -p tcp -m tcp --dport 135:139 -j DROP
    -A LOGDROPIN -p udp -m udp --dport 135:139 -j DROP
    -A LOGDROPIN -p tcp -m tcp --dport 445 -j DROP
    -A LOGDROPIN -p udp -m udp --dport 445 -j DROP
    -A LOGDROPIN -p tcp -m tcp --dport 500 -j DROP
    -A LOGDROPIN -p udp -m udp --dport 500 -j DROP
    -A LOGDROPIN -p tcp -m tcp --dport 513 -j DROP
    -A LOGDROPIN -p udp -m udp --dport 513 -j DROP
    -A LOGDROPIN -p tcp -m tcp --dport 520 -j DROP
    -A LOGDROPIN -p udp -m udp --dport 520 -j DROP
    -A LOGDROPIN -p tcp -m limit --limit 30/min -j LOG --log-prefix "Firewall: *TCP_IN Blocked* "
    -A LOGDROPIN -p udp -m limit --limit 30/min -j LOG --log-prefix "Firewall: *UDP_IN Blocked* "
    -A LOGDROPIN -p icmp -m limit --limit 30/min -j LOG --log-prefix "Firewall: *ICMP_IN Blocked* "
    -A LOGDROPIN -j DROP
    -A LOGDROPOUT -p tcp -m limit --limit 30/min -j LOG --log-prefix "Firewall: *TCP_OUT Blocked* "
    -A LOGDROPOUT -p udp -m limit --limit 30/min -j LOG --log-prefix "Firewall: *UDP_OUT Blocked* "
    -A LOGDROPOUT -p icmp -m limit --limit 30/min -j LOG --log-prefix "Firewall: *ICMP_OUT Blocked* "
    -A LOGDROPOUT -j DROP
    -A acctboth -s 10.0.0.22 -i ! lo -p tcp -m tcp --dport 80
    -A acctboth -d 10.0.0.22 -i ! lo -p tcp -m tcp --sport 80
    -A acctboth -s 10.0.0.22 -i ! lo -p tcp -m tcp --dport 25
    -A acctboth -d 10.0.0.22 -i ! lo -p tcp -m tcp --sport 25
    -A acctboth -s 10.0.0.22 -i ! lo -p tcp -m tcp --dport 110
    -A acctboth -d 10.0.0.22 -i ! lo -p tcp -m tcp --sport 110
    -A acctboth -s 10.0.0.22 -i ! lo -p icmp
    -A acctboth -d 10.0.0.22 -i ! lo -p icmp
    -A acctboth -s 10.0.0.22 -i ! lo -p tcp
    -A acctboth -d 10.0.0.22 -i ! lo -p tcp
    -A acctboth -s 10.0.0.22 -i ! lo -p udp
    -A acctboth -d 10.0.0.22 -i ! lo -p udp
    -A acctboth -s 10.0.0.22 -i ! lo
    -A acctboth -d 10.0.0.22 -i ! lo
    -A acctboth -s 10.0.0.243 -i ! lo -p tcp -m tcp --dport 80
    -A acctboth -d 10.0.0.243 -i ! lo -p tcp -m tcp --sport 80
    -A acctboth -s 10.0.0.243 -i ! lo -p tcp -m tcp --dport 25
    -A acctboth -d 10.0.0.243 -i ! lo -p tcp -m tcp --sport 25
    -A acctboth -s 10.0.0.243 -i ! lo -p tcp -m tcp --dport 110
    -A acctboth -d 10.0.0.243 -i ! lo -p tcp -m tcp --sport 110
    -A acctboth -s 10.0.0.243 -i ! lo -p icmp
    -A acctboth -d 10.0.0.243 -i ! lo -p icmp
    -A acctboth -s 10.0.0.243 -i ! lo -p tcp
    -A acctboth -d 10.0.0.243 -i ! lo -p tcp
    -A acctboth -s 10.0.0.243 -i ! lo -p udp
    -A acctboth -d 10.0.0.243 -i ! lo -p udp
    -A acctboth -s 10.0.0.243 -i ! lo
    -A acctboth -d 10.0.0.243 -i ! lo
    -A acctboth -s 10.0.0.209 -i ! lo -p tcp -m tcp --dport 80
    -A acctboth -d 10.0.0.209 -i ! lo -p tcp -m tcp --sport 80
    -A acctboth -s 10.0.0.209 -i ! lo -p tcp -m tcp --dport 25
    -A acctboth -d 10.0.0.209 -i ! lo -p tcp -m tcp --sport 25
    -A acctboth -s 10.0.0.209 -i ! lo -p tcp -m tcp --dport 110
    -A acctboth -d 10.0.0.209 -i ! lo -p tcp -m tcp --sport 110
    -A acctboth -s 10.0.0.209 -i ! lo -p icmp
    -A acctboth -d 10.0.0.209 -i ! lo -p icmp
    -A acctboth -s 10.0.0.209 -i ! lo -p tcp
    -A acctboth -d 10.0.0.209 -i ! lo -p tcp
    -A acctboth -s 10.0.0.209 -i ! lo -p udp
    -A acctboth -d 10.0.0.209 -i ! lo -p udp
    -A acctboth -s 10.0.0.209 -i ! lo
    -A acctboth -d 10.0.0.209 -i ! lo
    -A acctboth -s 10.0.0.249 -i ! lo -p tcp -m tcp --dport 80
    -A acctboth -d 10.0.0.249 -i ! lo -p tcp -m tcp --sport 80
    -A acctboth -s 10.0.0.249 -i ! lo -p tcp -m tcp --dport 25
    -A acctboth -d 10.0.0.249 -i ! lo -p tcp -m tcp --sport 25
    -A acctboth -s 10.0.0.249 -i ! lo -p tcp -m tcp --dport 110
    -A acctboth -d 10.0.0.249 -i ! lo -p tcp -m tcp --sport 110
    -A acctboth -s 10.0.0.249 -i ! lo -p icmp
    -A acctboth -d 10.0.0.249 -i ! lo -p icmp
    -A acctboth -s 10.0.0.249 -i ! lo -p tcp
    -A acctboth -d 10.0.0.249 -i ! lo -p tcp
    -A acctboth -s 10.0.0.249 -i ! lo -p udp
    -A acctboth -d 10.0.0.249 -i ! lo -p udp
    -A acctboth -s 10.0.0.249 -i ! lo
    -A acctboth -d 10.0.0.249 -i ! lo
    -A acctboth -i ! lo
    COMMIT
    # Completed on Wed Jan  2 16:23:12 2013

    # rpm -Va openssh\*
    Code:
    ..5....T  c /etc/ssh/sshd_config
    .M......    /usr/libexec/openssh/ssh-keysign
     
  14. Phylum

    Phylum Active Member

    Joined:
    Apr 20, 2010
    Messages:
    29
    Likes Received:
    0
    Trophy Points:
    1
    Re: cannot ssh into server sshd is up per status everything else works fine

    So I take it there's no real solution here - just start from scratch?
     
Loading...

Share This Page