Forum Replies Created
-
AuthorPosts
-
Steve92
ParticipantHi!
Yes, it was a copy/paste problem from MSWord (doesn’t like –) to terminal window !
I’ve to warn the future admin team… or use notepad to type documentation. 😉
Steve.
Steve92
ParticipantHi !
Thanks, the rules are well deleted but
sudo /etc/NX/nxserver --nodegroupdel Nodes_Group_01gives
NX> 500 ERROR: Invalid command: '–-nodegroupdel'
What’s wrong ?
Regards,
Steve.
Steve92
ParticipantHi!
So the symetric encryption key is not encrypted with public key of the node stored in
/var/NX/nx/.nx/config/authorized.crt
?
How is the symetric encryption key protected during exchange ?
I’ve noticed sometimes the public key of a node is deleted from /var/NX/nx/.nx/config/authorized.crt when a node is deleted but it doesn’t seem to be done in a systematic way.
When exactly a public key is deleted from /var/NX/nx/.nx/config/authorized.crt file ?
Is it the same logic when the node is deleted from UI or with the command line ?
Thanks,
Regards,
Steve.
Steve92
ParticipantHi!
When I try to connect ECS from Enterprise Client with Kerberos MS SSPI, I get this error in session log.
What could be the prob’ ?
Thanks,
Steve.
—–
sspi_init_sec_context_test: Authentication mechanism ‘Kerberos’ is not supported.
ssh_sspi_error: The target was not recognized.
ssh_sspi_error: The requested security package does not exist.
ssh_sspi_error: The requested security package does not exist.
ssh_sspi_indicate_mech: ERROR! No more mechanisms.
12612 14116 17:08:09 620 NXGssapiPrepareMech: ERROR! Cannot indicate mech.
ialized session at 0x0000000003cf10a0.
12128 5448 2025-03-14 17:07:43 513.591 ClientSession: Starting session at 0x0000000003cf10a0.
12128 5448 2025-03-14 17:07:43 515.416 ClientSession: Going to start session ‘C:\Users\xyz\Documents\NoMachine\ECS RIE KERB.nxs’.
12128 5448 2025-03-14 17:07:43 532.196 Connection: Initializing connection at 0x0000000007786370.
12128 5448 2025-03-14 17:07:43 537.183 Connection: Initialized connection at 0x0000000007786370.
12128 5448 2025-03-14 17:07:43 537.183 Connection: Starting connection at 0x0000000007786370.
12128 5448 2025-03-14 17:07:43 537.183 ClientDaemonConnector: Starting a new connection to host ‘w.x.y.z’ on port ‘4000’.
12128 5448 2025-03-14 17:07:43 538.672 Connection: Started connection at 0x0000000007786370.
12128 5448 2025-03-14 17:07:43 538.672 ClientSession: Started session at 0x0000000003cf10a0.
Info: Slave server running with pid 16608.
Info: Listening to slave connections on port 35299.
Info: Connection to w.x.y.z port 4000 started at 17:07:43 553.232.
12128 5448 2025-03-14 17:07:43 555.304 Main: Entering the GUI event loop.
12128 14132 2025-03-14 17:07:44 841.855 ClientSession: A valid certificate for this server was found.
12128 14132 2025-03-14 17:08:09 620.348 DaemonLogin/DaemonLogin: ERROR! Gss oid not specified.
Error: Gss oid not specified.
12128 19952 2025-03-14 17:08:09 623.362 DaemonClientApplication/DaemonClientApplication: WARNING! Session terminated abnormally.
12128 19952 2025-03-14 17:08:09 623.362 DaemonClientApplication/DaemonClientApplication: WARNING! Error is 22, ‘Invalid argument’.
Warning: Connection to w.x.y.z port 4000 failed at 17:08:09 623.362.
Warning: Error is 22, ‘Invalid argument’.
12128 5448 2025-03-14 17:08:09 624.553 Connection: Connection at 0x0000000007786370 failed.
12128 5448 2025-03-14 17:08:09 624.553 ClientSession: Runnable at 0x0000000007786370 caused the session at 0x0000000003cf10a0 to fail.
12128 5448 2025-03-14 17:08:09 624.553 ClientSession: Failing reason is ‘Impossible de se connecter au serveur.
L’erreur est 22 : Argument non valable’.
12128 5448 2025-03-14 17:08:09 636.440 ClientSession: Stopping session at 0x0000000003cf10a0.
12128 5448 2025-03-14 17:08:09 659.110 ClientSession: Destroying display client.
Steve92
ParticipantHi
Any idea ?Steve92
ParticipantHi
Yes, it would be for inverse connection cases.Steve92
ParticipantHi,
After reboot RAM usage is much more reasonable.
But I’d like advice to size the RAM.
How much RAM is needed on ECS for:
– 10 concurent users ?
– 20 concurrent users ?
– 50 concurrent users ?From what number a cluster is advised ?
Thanks,
Regards,
Steve.
Steve92
ParticipantThanks for this more recent link but alas it doesn’t deal with ECS sizing.
Steve92
ParticipantHi,
No guest desktop sharing.
Thanks for taking into account this idea.
Steve.
Steve92
ParticipantHi
All settings are in Windows 11 registry.(No krk5… Files)
I suppose I’ve to use ksetup ?Thanks
SteveSteve92
ParticipantHi!
Is this article still OK for v8 ?
Steve.
Steve92
ParticipantHi,
I found this in a 1-year-old post on Reddit:
“If you want to install NoMachine Enterprise client on Windows, it works and you dont need admin rights.
If you are having user that does not have admin rights NoMachine Enterprise client will install in your home folder and you can use it to connect to the other machines.”Please, could you confirm this statement ?
Thanks.
Regards,
Steve.
February 12, 2025 at 14:23 in reply to: Tool to simplify adding of multiple users’ public keys on ECS? #51794Steve92
ParticipantHello,
Ansible could be an interesting solution.
But for the moment, could you please confirm owner, group and permissions, created manually, are OK on the following files and folders of this ECS machine ?
[my_user@ECSDR ~]$ pwd
/home/my_user
[my_user@ECSDR ~]$ ls -al
total 116
drwx——. 17 my_user my_user 4096 26 nov. 11:06 .
drwxr-xr-x. 11 root root 149 21 janv. 15:27 ..
drwx——. 30 my_user my_user 4096 11 févr. 10:44 .nx[my_user@ECSDR ~]$ ls -al .nx
total 44
drwx——. 30 my_user my_user 4096 11 févr. 10:44 .
drwx——. 17 my_user my_user 4096 26 nov. 11:06 ..
drwx——. 2 my_user my_user 63 3 févr. 17:57 config[my_user@ECSDR ~]$ ls -al .nx/config
total 24
drwx——. 2 my_user my_user 63 3 févr. 17:57 .
drwx——. 30 my_user my_user 4096 11 févr. 10:44 ..
-rw——-. 1 my_user my_user 982 3 févr. 13:38 authorized.crtThanks,
Regards,
Steve.February 10, 2025 at 21:18 in reply to: Tool to simplify adding of multiple users’ public keys on ECS? #51768Steve92
ParticipantHello,
Nothing like
sudo /etc/NX/nxserver --keyadd /home/user/node.localhost.id_rsa.pub
but to update
<user’s home>/.nx/config/authorized.crt
instead of /var/NX/nx/.nx/config/authorized.crt ?
On ECS, I’ve noticed that some users don’t have the folders <user’s home>/.nx/config
When <user’s home>/.nx is created ?
Thanks,
Regards,
Steve.
Steve92
ParticipantHello,
It was actually a PAM (SELinux, Pluggable Authentication Modules) configuration problem.
The VM I was given for the POC has security hardening (I didn’t know that… but it’s a good thing to have a POC configuration matching the aimed one).
I solved the problem by following NoMachine – Troubleshooting LDAP And PAM Issues On Linux For Connections By NX Protocol – Knowledge Base
SSH access was OK so I used its PAM config file:
cp /etc/pam.d/nx /etc/pam.d/nx.ori
cp /etc/pam.d/sshd /etc/pam.d/nxNow, access from “!M Client” to ECS is OK with all protocols (SSH, NX & HTTPS). I can add nodes from the client module.
The nx and sshd PAM config files are now the same.
Do I need to do more testing to validate the solution ?
Thanks and happy new year !
Regards,
Steve.
-
AuthorPosts