Skip to content
This repository was archived by the owner on Jan 22, 2025. It is now read-only.
This repository was archived by the owner on Jan 22, 2025. It is now read-only.

Failed to get a signed key from the CA: ... received error response from keybase api: DB error (error 2623) #100

Description

@wsot

I have (following the instructions at https://keybase-ssh-ca-bot.readthedocs.io/en/latest/getting\_started.html) configured the Keybase SSH CA bot (using Docker), and have configured a second 'target server' with the CA etc.

When I try to connect to the 'target server' using kssh, I get the message
Failed to get a signed key from the CA: failed to get config: Failed to load config(s): received error response from keybase api: DB error (error 2623)

I can see in my .ssh folder there are the files keybase-signed-key-- and keybase-signed-key--.pub, but if I try to use keybase-signed-key-- or keybase-signed-key--.pub to SSH to the server directly I get Permission denied (publickey).

I am able to ping @mybotname in the relevant channel for SSH access, and get back a pong @mybotname as I would expect.

Looking at other issues (e.g. #64) it looks like others see some kind of "Keybase SSH Provision chat in my team" - I see nothing like that in the channel at all. However, if I manually post a Signature_Request:{"ssh_public_key":"xxxxxxxx", ,"uuid":"xxxxxxxxx-xxxxx-xxxx-xxxxxx-xxxxxxxxxxx"}, I get back a Signature_Response:{"signed_key":xxxx" in the channel, so it looks like the bot itself is actually working.
(Note, for the UUID I literally used xxxxxxxxx-xxxxx-xxxx-xxxxxx-xxxxxxxxxxx in case that matters.

So it kind of looks like kssh is failing to post the relevant messages via Keybase? I've tried this on two machines with two keybase users and two different OSs and had the same error.

Extra details (copied from a post I made on Reddit)

I also described this in a reddit post: https://www.reddit.com/r/Keybase/comments/gubooe/keybase_ssh_ca_anyone_got_it_working_received/

I've been trying to get the Keybase teams-based SSH CA working (described https://keybase.io/blog/keybase-ssh-ca) with no success.
I've done all the set-up steps, but when I actually try to use kssh to get to the destination machine (the one set up with the CA, not the one with the bot) I always get the error:
Failed to get a signed key from the CA: failed to get config: Failed to load config(s): received error response from keybase api: DB error (error 2623)

I followed the instructions here: https://keybase-ssh-ca-bot.readthedocs.io/en/latest/getting_started.html
So, I have:

  1. A machine running the bot (Set up using the paper key, and using docker, as described) with a specific bot user (I'll call it @Mybot)
  2. A destination machine I want to manage SSH permissions on (with the ca.pub file and /etc/ssh/auth_principals/ files containing the team names, and the TrustedUserCAKeys and AuthorizedPrincipalsFile in the sshd_config as per instructions

Note that I added the bot as a normal user in the channel, not by installing it as a bot. I've tried having it installed as a bot, and also as full user and neither worked.
For reference, the instructions don't specify whether it should be installed as a bot or added as a user (or I don't find it clear, anyway):

Then create {TEAM}.ssh.staging, {TEAM}.ssh.production, {TEAM}.ssh.root_everywhere as new Keybase subteams and add the bot to those subteams. Add users to those subteams based off of the permissions you wish to grant different users

Note that I pulled down the repo using HTTPS rather than SSH as I didn't have SSH keys set up on the server - using the url git clone https://github.com/keybase/bot-sshca.git

I have added the bot to the relevant channels, and verified that I can ping it - i.e. if I ping @mybot then I get pong @myuser. There is nothing in the logs on docker that would make me think it isn't behaving correctly.

2020/06/01 01:24:57 - Subscription: Read -> ok [time=21m1.759092887s]
2020/06/01 01:24:58 + Subscription: Read
2020/06/01 01:24:58 - Subscription: Read -> ok [time=4.447664ms]
2020/06/01 01:24:58 + Subscription: Read

I've tried this using both a Linux client and a Mac client trying to use kssh (although in both cases with the same user). Does anyone have any suggestions as to what to try next? (I haven't opened a github issue or pinged dworken as suggested at the end of the troubleshooting guide - though I'd try the community before bugging them there).

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    ackedbugSomething isn't working

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions