bin/171809: sshd EVP_CipherInit: set key failed for aes128-cbc [preauth]

freebsd at freebsd at
Thu Sep 20 11:30:10 UTC 2012

>Number:         171809
>Category:       bin
>Synopsis:       sshd EVP_CipherInit: set key failed for aes128-cbc [preauth]
>Confidential:   no
>Severity:       non-critical
>Priority:       low
>Responsible:    freebsd-bugs
>State:          open
>Class:          sw-bug
>Submitter-Id:   current-users
>Arrival-Date:   Thu Sep 20 11:30:09 UTC 2012
>Originator:     freebsd at
>Release:        FreeBSD 10.0-CURRENT i386
System: FreeBSD cakebox.tis 10.0-CURRENT FreeBSD 10.0-CURRENT #0 r240553M: Tue Sep 18 00:11:57 CEST 2012 root at cakebox.tis:/usr/obj/export/src/sys/net5501 i386

Geode LX: Soekris net5501 comBIOS ver. 1.33 20070103 Copyright (C) 2000-2007
glxsb0: <AMD Geode LX Security Block (AES-128-CBC, RNG)> mem 0xa0000000-0xa0003fff irq 10 at device 1.2 on pci0

OpenSSH_6.1p1, OpenSSL 1.0.1c 10 May 2012

	Some ssh clients can't connect due this error:
Sep 20 13:07:52 cakebox sshd[33872]: fatal: cipher_init: EVP_CipherInit: set key failed for aes128-cbc [preauth]

	This might be related:
	but that's about ctr and not cbc

	build and run current on a machine with glxsb, connect with this ssh:
OpenSSH_5.0 NetBSD_Secure_Shell-20080403, OpenSSL 0.9.9-dev 09 May 2008
	FreeBSDs ssh and Linux (OpenSSH_5.9p1 Debian-5ubuntu1, OpenSSL 1.0.1 14 Mar 2012)
	have no issues.


	unknown (I could probably disable glxsb0 but that would be a lame escape)

More information about the freebsd-bugs mailing list