# Knife ec2 failing on sshd

**URL:** <https://discourse.chef.io/t/knife-ec2-failing-on-sshd/6380>\
**Category:** Chef Infra (archive)\
**Created:** [March 6, 2015, 10:16pm UTC](https://discourse.chef.io/t/knife-ec2-failing-on-sshd/6380 "2015-03-06T22:16:52Z")\
**Posts on this page:** 13\
**Page:** 1

<div class="post-metadata">

**Author:** ![Michael\_Lindsay](https://avatars.discourse-cdn.com/v4/letter/m/dec6dc/32.png) [@Michael\_Lindsay](https://discourse.chef.io/u/Michael_Lindsay)\
**Post date:** [March 6, 2015, 10:16pm UTC](https://discourse.chef.io/t/knife-ec2-failing-on-sshd/6380/1 "2015-03-06T22:16:52Z")

</div>

Hello everyone…

I’m attempting my first knife ec2 create commands for building instances  
inside a VPC.

The problem I’m facing is that “Waiting for sshd access to become  
available…” Never completes. What’s weird (and flies in the face of  
what I thought was going on) is that while I’m watching little dots appear,  
in another terminal window on the same workstation, using the same identity  
file, user, and I think hostname (EIP) that the knife command is using, I  
CAN ssh into the instance.  
Any ideas what might cause this?

- Michael

---

<div class="post-metadata">

**Author:** ![luckymike](https://sea2.discourse-cdn.com/flex016/user_avatar/discourse.chef.io/luckymike/32/134_2.png) [@luckymike](https://discourse.chef.io/u/luckymike)\
**Post date:** [March 6, 2015, 10:19pm UTC](https://discourse.chef.io/t/knife-ec2-failing-on-sshd/6380/2 "2015-03-06T22:19:54Z")

</div>

Hi Michael,

I generally use Cloudformation for all my VPC instances, so have not  
attempted a direct bootstrap. Have you confirmed that the inbound and  
outbound security group and ACL rules allow traffic both directions on 22,  
80, 443, and the ephemeral ports?

--  
_Michael F. Weinberg | Director of Operations_  
[http://heavywaterops.com](http://heavywaterops.com) | @heavywaterops

On Fri, Mar 6, 2015 at 2:16 PM, Michael Lindsay [mlindsay@metrodigi.com](mailto:mlindsay@metrodigi.com)  
wrote:

> Hello everyone…
> 
> I’m attempting my first knife ec2 create commands for building instances  
> inside a VPC.
> 
> The problem I'm facing is that "Waiting for sshd access to become  
> available...." Never completes. What's weird (and flies in the face of  
> what I thought was going on) is that while I'm watching little dots appear,  
> in another terminal window on the same workstation, using the same identity  
> file, user, and I think hostname (EIP) that the knife command is using, I  
> CAN ssh into the instance.  
> Any ideas what might cause this?
> 
> - Michael

---

<div class="post-metadata">

**Author:** ![Michael\_Lindsay](https://avatars.discourse-cdn.com/v4/letter/m/dec6dc/32.png) [@Michael\_Lindsay](https://discourse.chef.io/u/Michael_Lindsay)\
**Post date:** [March 6, 2015, 10:29pm UTC](https://discourse.chef.io/t/knife-ec2-failing-on-sshd/6380/3 "2015-03-06T22:29:52Z")

</div>

Hi again Michael 🙂 I'm new to VPC, but I feel like I've poured over all  
the settings there. Would the behavior be different with knife than ssh on  
the same workstation in this regard?

On Fri, Mar 6, 2015 at 2:19 PM, Michael Weinberg [michael@hw-ops.com](mailto:michael@hw-ops.com) wrote:

> Hi Michael,
> 
> I generally use Cloudformation for all my VPC instances, so have not  
> attempted a direct bootstrap. Have you confirmed that the inbound and  
> outbound security group and ACL rules allow traffic both directions on 22,  
> 80, 443, and the ephemeral ports?
> 
> --  
> _Michael F. Weinberg | Director of Operations_  
> [http://heavywaterops.com](http://heavywaterops.com) | @heavywaterops
> 
> On Fri, Mar 6, 2015 at 2:16 PM, Michael Lindsay [mlindsay@metrodigi.com](mailto:mlindsay@metrodigi.com)  
> wrote:
> 
> > Hello everyone…
> > 
> > I’m attempting my first knife ec2 create commands for building instances  
> > inside a VPC.
> > 
> > The problem I'm facing is that "Waiting for sshd access to become  
> > available...." Never completes. What's weird (and flies in the face of  
> > what I thought was going on) is that while I'm watching little dots appear,  
> > in another terminal window on the same workstation, using the same identity  
> > file, user, and I think hostname (EIP) that the knife command is using, I  
> > CAN ssh into the instance.  
> > Any ideas what might cause this?
> > 
> > - Michael

---

<div class="post-metadata">

**Author:** ![luckymike](https://sea2.discourse-cdn.com/flex016/user_avatar/discourse.chef.io/luckymike/32/134_2.png) [@luckymike](https://discourse.chef.io/u/luckymike)\
**Post date:** [March 6, 2015, 10:32pm UTC](https://discourse.chef.io/t/knife-ec2-failing-on-sshd/6380/4 "2015-03-06T22:32:36Z")

</div>

No, it shouldn't be. But I don't know what is actually happening during  
'waiting for sshd,' so on the off chance there's some additional  
communication there I thought I'd suggest it.

--  
_Michael F. Weinberg | Director of Operations_  
[http://heavywaterops.com](http://heavywaterops.com) | @heavywaterops

On Fri, Mar 6, 2015 at 2:29 PM, Michael Lindsay [mlindsay@metrodigi.com](mailto:mlindsay@metrodigi.com)  
wrote:

> Hi again Michael 🙂 I'm new to VPC, but I feel like I've poured over all  
> the settings there. Would the behavior be different with knife than ssh on  
> the same workstation in this regard?
> 
> On Fri, Mar 6, 2015 at 2:19 PM, Michael Weinberg [michael@hw-ops.com](mailto:michael@hw-ops.com)  
> wrote:
> 
> > Hi Michael,
> > 
> > I generally use Cloudformation for all my VPC instances, so have not  
> > attempted a direct bootstrap. Have you confirmed that the inbound and  
> > outbound security group and ACL rules allow traffic both directions on 22,  
> > 80, 443, and the ephemeral ports?
> > 
> > --  
> > _Michael F. Weinberg | Director of Operations_  
> > [http://heavywaterops.com](http://heavywaterops.com) | @heavywaterops
> > 
> > On Fri, Mar 6, 2015 at 2:16 PM, Michael Lindsay [mlindsay@metrodigi.com](mailto:mlindsay@metrodigi.com)  
> > wrote:
> > 
> > > Hello everyone…
> > > 
> > > I’m attempting my first knife ec2 create commands for building instances  
> > > inside a VPC.
> > > 
> > > The problem I'm facing is that "Waiting for sshd access to become  
> > > available...." Never completes. What's weird (and flies in the face of  
> > > what I thought was going on) is that while I'm watching little dots appear,  
> > > in another terminal window on the same workstation, using the same identity  
> > > file, user, and I think hostname (EIP) that the knife command is using, I  
> > > CAN ssh into the instance.  
> > > Any ideas what might cause this?
> > > 
> > > - Michael

---

<div class="post-metadata">

**Author:** ![jdunn](https://sea2.discourse-cdn.com/flex016/user_avatar/discourse.chef.io/jdunn/32/1800_2.png) [@jdunn](https://discourse.chef.io/u/jdunn)\
**Post date:** [March 6, 2015, 10:44pm UTC](https://discourse.chef.io/t/knife-ec2-failing-on-sshd/6380/5 "2015-03-06T22:44:03Z")

</div>

It's not doing anything besides trying to open a TCP connection to the SSH port:

> <https://github.com/chef/knife-ec2/blob/main/lib/chef/knife/ec2_server_create.rb#L395-L398>

and

> <https://github.com/chef/knife-ec2/blob/main/lib/chef/knife/ec2_server_create.rb#L909-L938>

- Julian

On Fri, Mar 6, 2015 at 4:32 PM, Michael Weinberg [michael@hw-ops.com](mailto:michael@hw-ops.com) wrote:

> No, it shouldn't be. But I don't know what is actually happening during  
> 'waiting for sshd,' so on the off chance there's some additional  
> communication there I thought I'd suggest it.
> 
> --  
> Michael F. Weinberg | Director of Operations  
> [http://heavywaterops.com](http://heavywaterops.com) | @heavywaterops
> 
> On Fri, Mar 6, 2015 at 2:29 PM, Michael Lindsay [mlindsay@metrodigi.com](mailto:mlindsay@metrodigi.com)  
> wrote:
> 
> > Hi again Michael 🙂 I'm new to VPC, but I feel like I've poured over all  
> > the settings there. Would the behavior be different with knife than ssh on  
> > the same workstation in this regard?
> > 
> > On Fri, Mar 6, 2015 at 2:19 PM, Michael Weinberg [michael@hw-ops.com](mailto:michael@hw-ops.com)  
> > wrote:
> > 
> > > Hi Michael,
> > > 
> > > I generally use Cloudformation for all my VPC instances, so have not  
> > > attempted a direct bootstrap. Have you confirmed that the inbound and  
> > > outbound security group and ACL rules allow traffic both directions on 22,  
> > > 80, 443, and the ephemeral ports?
> > > 
> > > --  
> > > Michael F. Weinberg | Director of Operations  
> > > [http://heavywaterops.com](http://heavywaterops.com) | @heavywaterops
> > > 
> > > On Fri, Mar 6, 2015 at 2:16 PM, Michael Lindsay [mlindsay@metrodigi.com](mailto:mlindsay@metrodigi.com)  
> > > wrote:
> > > 
> > > > Hello everyone…
> > > > 
> > > > I’m attempting my first knife ec2 create commands for building instances  
> > > > inside a VPC.
> > > > 
> > > > The problem I'm facing is that "Waiting for sshd access to become  
> > > > available...." Never completes. What's weird (and flies in the face of what  
> > > > I thought was going on) is that while I'm watching little dots appear, in  
> > > > another terminal window on the same workstation, using the same identity  
> > > > file, user, and I think hostname (EIP) that the knife command is using, I  
> > > > CAN ssh into the instance.
> > > > 
> > > > Any ideas what might cause this?
> > > > 
> > > > - Michael

--  
[Julian C. Dunn [jdunn@aquezada.com](mailto:jdunn@aquezada.com) \* Sorry, I'm ]  
[WWW: [http://www.aquezada.com/staff/julian](http://www.aquezada.com/staff/julian) \* only Web 1.0 ]  
[gopher://sdf.org/1/users/keymaker/ \* compliant!]  
[PGP: 91B3 7A9D 683C 7C16 715F 442C 6065 D533 FDC2 05B9]

---

<div class="post-metadata">

**Author:** ![Darren\_Dyke](https://sea2.discourse-cdn.com/flex016/user_avatar/discourse.chef.io/darren_dyke/32/165_2.png) [@Darren\_Dyke](https://discourse.chef.io/u/Darren_Dyke)\
**Post date:** [March 6, 2015, 10:48pm UTC](https://discourse.chef.io/t/knife-ec2-failing-on-sshd/6380/6 "2015-03-06T22:48:09Z")

</div>

Hello, are you trying to configure a node on a private subnet? If so are  
you supplying the --ssh-gateway option/configure ssh config proxies?

On Fri, Mar 6, 2015 at 5:32 PM, Michael Weinberg [michael@hw-ops.com](mailto:michael@hw-ops.com) wrote:

> No, it shouldn't be. But I don't know what is actually happening during  
> 'waiting for sshd,' so on the off chance there's some additional  
> communication there I thought I'd suggest it.
> 
> --  
> _Michael F. Weinberg | Director of Operations_  
> [http://heavywaterops.com](http://heavywaterops.com) | @heavywaterops
> 
> On Fri, Mar 6, 2015 at 2:29 PM, Michael Lindsay [mlindsay@metrodigi.com](mailto:mlindsay@metrodigi.com)  
> wrote:
> 
> > Hi again Michael 🙂 I'm new to VPC, but I feel like I've poured over all  
> > the settings there. Would the behavior be different with knife than ssh on  
> > the same workstation in this regard?
> > 
> > On Fri, Mar 6, 2015 at 2:19 PM, Michael Weinberg [michael@hw-ops.com](mailto:michael@hw-ops.com)  
> > wrote:
> > 
> > > Hi Michael,
> > > 
> > > I generally use Cloudformation for all my VPC instances, so have not  
> > > attempted a direct bootstrap. Have you confirmed that the inbound and  
> > > outbound security group and ACL rules allow traffic both directions on 22,  
> > > 80, 443, and the ephemeral ports?
> > > 
> > > --  
> > > _Michael F. Weinberg | Director of Operations_  
> > > [http://heavywaterops.com](http://heavywaterops.com) | @heavywaterops
> > > 
> > > On Fri, Mar 6, 2015 at 2:16 PM, Michael Lindsay [mlindsay@metrodigi.com](mailto:mlindsay@metrodigi.com)  
> > > wrote:
> > > 
> > > > Hello everyone…
> > > > 
> > > > I’m attempting my first knife ec2 create commands for building  
> > > > instances inside a VPC.
> > > > 
> > > > The problem I'm facing is that "Waiting for sshd access to become  
> > > > available...." Never completes. What's weird (and flies in the face of  
> > > > what I thought was going on) is that while I'm watching little dots appear,  
> > > > in another terminal window on the same workstation, using the same identity  
> > > > file, user, and I think hostname (EIP) that the knife command is using, I  
> > > > CAN ssh into the instance.  
> > > > Any ideas what might cause this?
> > > > 
> > > > - Michael

---

<div class="post-metadata">

**Author:** ![Michael\_Lindsay](https://avatars.discourse-cdn.com/v4/letter/m/dec6dc/32.png) [@Michael\_Lindsay](https://discourse.chef.io/u/Michael_Lindsay)\
**Post date:** [March 6, 2015, 11:04pm UTC](https://discourse.chef.io/t/knife-ec2-failing-on-sshd/6380/7 "2015-03-06T23:04:09Z")

</div>

@Julian: hadn't thought to look at the source code, that's good info (and I  
can see why the dots roll out more slowly 😉 ). I'm not connecting to an  
ubuntu instance so looks like it wouldn't be TCP connection in the second  
git file but instead something from here?

> <https://github.com/chef/knife-ec2/blob/main/lib/chef/knife/ec2_server_create.rb#L748-L769>

@Darren: It's a public subnet, so no proxy required

On Fri, Mar 6, 2015 at 2:48 PM, Darren Dyke [dwdyke@gmail.com](mailto:dwdyke@gmail.com) wrote:

> Hello, are you trying to configure a node on a private subnet? If so are  
> you supplying the --ssh-gateway option/configure ssh config proxies?
> 
> On Fri, Mar 6, 2015 at 5:32 PM, Michael Weinberg [michael@hw-ops.com](mailto:michael@hw-ops.com)  
> wrote:
> 
> > No, it shouldn't be. But I don't know what is actually happening during  
> > 'waiting for sshd,' so on the off chance there's some additional  
> > communication there I thought I'd suggest it.
> > 
> > --  
> > _Michael F. Weinberg | Director of Operations_  
> > [http://heavywaterops.com](http://heavywaterops.com) | @heavywaterops
> > 
> > On Fri, Mar 6, 2015 at 2:29 PM, Michael Lindsay [mlindsay@metrodigi.com](mailto:mlindsay@metrodigi.com)  
> > wrote:
> > 
> > > Hi again Michael 🙂 I'm new to VPC, but I feel like I've poured over  
> > > all the settings there. Would the behavior be different with knife than  
> > > ssh on the same workstation in this regard?
> > > 
> > > On Fri, Mar 6, 2015 at 2:19 PM, Michael Weinberg [michael@hw-ops.com](mailto:michael@hw-ops.com)  
> > > wrote:
> > > 
> > > > Hi Michael,
> > > > 
> > > > I generally use Cloudformation for all my VPC instances, so have not  
> > > > attempted a direct bootstrap. Have you confirmed that the inbound and  
> > > > outbound security group and ACL rules allow traffic both directions on 22,  
> > > > 80, 443, and the ephemeral ports?
> > > > 
> > > > --  
> > > > _Michael F. Weinberg | Director of Operations_  
> > > > [http://heavywaterops.com](http://heavywaterops.com) | @heavywaterops
> > > > 
> > > > On Fri, Mar 6, 2015 at 2:16 PM, Michael Lindsay \<[mlindsay@metrodigi.com](mailto:mlindsay@metrodigi.com)
> > > > 
> > > > > wrote:
> > > > 
> > > > > Hello everyone…
> > > > > 
> > > > > I’m attempting my first knife ec2 create commands for building  
> > > > > instances inside a VPC.
> > > > > 
> > > > > The problem I'm facing is that "Waiting for sshd access to become  
> > > > > available...." Never completes. What's weird (and flies in the face of  
> > > > > what I thought was going on) is that while I'm watching little dots appear,  
> > > > > in another terminal window on the same workstation, using the same identity  
> > > > > file, user, and I think hostname (EIP) that the knife command is using, I  
> > > > > CAN ssh into the instance.  
> > > > > Any ideas what might cause this?
> > > > > 
> > > > > - Michael

---

<div class="post-metadata">

**Author:** ![Michael\_Lindsay](https://avatars.discourse-cdn.com/v4/letter/m/dec6dc/32.png) [@Michael\_Lindsay](https://discourse.chef.io/u/Michael_Lindsay)\
**Post date:** [March 6, 2015, 11:19pm UTC](https://discourse.chef.io/t/knife-ec2-failing-on-sshd/6380/8 "2015-03-06T23:19:57Z")

</div>

@Julian, it did find it's way to tcp\_test\_ssh after all. Running with  
Debug enabled I can see 'No ssh gateway found'. Furthermore I can see it  
is trying to connect to the Private IP Address and not the EIP that I  
provided. Which explains the difference between my ssh and knife's... Just  
looking for a fix for that now.

- M

On Fri, Mar 6, 2015 at 3:04 PM, Michael Lindsay [mlindsay@metrodigi.com](mailto:mlindsay@metrodigi.com)  
wrote:

> @Julian: hadn't thought to look at the source code, that's good info (and  
> I can see why the dots roll out more slowly 😉 ). I'm not connecting to  
> an ubuntu instance so looks like it wouldn't be TCP connection in the  
> second git file but instead something from here?
> 
> [https://github.com/chef/knife-ec2/blob/master/lib/chef/knife/ec2\_server\_create.rb#L748-L769](https://github.com/chef/knife-ec2/blob/master/lib/chef/knife/ec2_server_create.rb#L748-L769)
> 
> @Darren: It's a public subnet, so no proxy required
> 
> On Fri, Mar 6, 2015 at 2:48 PM, Darren Dyke [dwdyke@gmail.com](mailto:dwdyke@gmail.com) wrote:
> 
> > Hello, are you trying to configure a node on a private subnet? If so are  
> > you supplying the --ssh-gateway option/configure ssh config proxies?
> > 
> > On Fri, Mar 6, 2015 at 5:32 PM, Michael Weinberg [michael@hw-ops.com](mailto:michael@hw-ops.com)  
> > wrote:
> > 
> > > No, it shouldn't be. But I don't know what is actually happening during  
> > > 'waiting for sshd,' so on the off chance there's some additional  
> > > communication there I thought I'd suggest it.
> > > 
> > > --  
> > > _Michael F. Weinberg | Director of Operations_  
> > > [http://heavywaterops.com](http://heavywaterops.com) | @heavywaterops
> > > 
> > > On Fri, Mar 6, 2015 at 2:29 PM, Michael Lindsay [mlindsay@metrodigi.com](mailto:mlindsay@metrodigi.com)  
> > > wrote:
> > > 
> > > > Hi again Michael 🙂 I'm new to VPC, but I feel like I've poured over  
> > > > all the settings there. Would the behavior be different with knife than  
> > > > ssh on the same workstation in this regard?
> > > > 
> > > > On Fri, Mar 6, 2015 at 2:19 PM, Michael Weinberg [michael@hw-ops.com](mailto:michael@hw-ops.com)  
> > > > wrote:
> > > > 
> > > > > Hi Michael,
> > > > > 
> > > > > I generally use Cloudformation for all my VPC instances, so have not  
> > > > > attempted a direct bootstrap. Have you confirmed that the inbound and  
> > > > > outbound security group and ACL rules allow traffic both directions on 22,  
> > > > > 80, 443, and the ephemeral ports?
> > > > > 
> > > > > --  
> > > > > _Michael F. Weinberg | Director of Operations_  
> > > > > [http://heavywaterops.com](http://heavywaterops.com) | @heavywaterops
> > > > > 
> > > > > On Fri, Mar 6, 2015 at 2:16 PM, Michael Lindsay \<  
> > > > > [mlindsay@metrodigi.com](mailto:mlindsay@metrodigi.com)\> wrote:
> > > > > 
> > > > > > Hello everyone…
> > > > > > 
> > > > > > I’m attempting my first knife ec2 create commands for building  
> > > > > > instances inside a VPC.
> > > > > > 
> > > > > > The problem I'm facing is that "Waiting for sshd access to become  
> > > > > > available...." Never completes. What's weird (and flies in the face of  
> > > > > > what I thought was going on) is that while I'm watching little dots appear,  
> > > > > > in another terminal window on the same workstation, using the same identity  
> > > > > > file, user, and I think hostname (EIP) that the knife command is using, I  
> > > > > > CAN ssh into the instance.  
> > > > > > Any ideas what might cause this?
> > > > > > 
> > > > > > - Michael

---

<div class="post-metadata">

**Author:** ![Darren\_Dyke](https://sea2.discourse-cdn.com/flex016/user_avatar/discourse.chef.io/darren_dyke/32/165_2.png) [@Darren\_Dyke](https://discourse.chef.io/u/Darren_Dyke)\
**Post date:** [March 6, 2015, 11:36pm UTC](https://discourse.chef.io/t/knife-ec2-failing-on-sshd/6380/9 "2015-03-06T23:36:25Z")

</div>

@Michael L.

If you are using the --associate-eip flag, try setting  
"--server-connect-attribute public\_ip\_address" See below from the ec2  
server create:

> <https://github.com/chef/knife-ec2/blob/main/lib/chef/knife/ec2_server_create.rb#L260-L264>

option :server\_connect\_attribute, :long =\> "--server-connect-attribute  
ATTRIBUTE", :short =\> "-a ATTRIBUTE", :description =\> "The EC2 server  
attribute to use for SSH connection. Use this attr for creating VPC  
instances along with --associate-eip", :default =\> nil

On Fri, Mar 6, 2015 at 6:19 PM, Michael Lindsay [mlindsay@metrodigi.com](mailto:mlindsay@metrodigi.com)  
wrote:

> @Julian, it did find it's way to tcp\_test\_ssh after all. Running with  
> Debug enabled I can see 'No ssh gateway found'. Furthermore I can see it  
> is trying to connect to the Private IP Address and not the EIP that I  
> provided. Which explains the difference between my ssh and knife's... Just  
> looking for a fix for that now.
> 
> - M
> 
> On Fri, Mar 6, 2015 at 3:04 PM, Michael Lindsay [mlindsay@metrodigi.com](mailto:mlindsay@metrodigi.com)  
> wrote:
> 
> > @Julian: hadn't thought to look at the source code, that's good info (and  
> > I can see why the dots roll out more slowly 😉 ). I'm not connecting to  
> > an ubuntu instance so looks like it wouldn't be TCP connection in the  
> > second git file but instead something from here?
> > 
> > [https://github.com/chef/knife-ec2/blob/master/lib/chef/knife/ec2\_server\_create.rb#L748-L769](https://github.com/chef/knife-ec2/blob/master/lib/chef/knife/ec2_server_create.rb#L748-L769)
> > 
> > @Darren: It's a public subnet, so no proxy required
> > 
> > On Fri, Mar 6, 2015 at 2:48 PM, Darren Dyke [dwdyke@gmail.com](mailto:dwdyke@gmail.com) wrote:
> > 
> > > Hello, are you trying to configure a node on a private subnet? If so are  
> > > you supplying the --ssh-gateway option/configure ssh config proxies?
> > > 
> > > On Fri, Mar 6, 2015 at 5:32 PM, Michael Weinberg [michael@hw-ops.com](mailto:michael@hw-ops.com)  
> > > wrote:
> > > 
> > > > No, it shouldn't be. But I don't know what is actually happening during  
> > > > 'waiting for sshd,' so on the off chance there's some additional  
> > > > communication there I thought I'd suggest it.
> > > > 
> > > > --  
> > > > _Michael F. Weinberg | Director of Operations_  
> > > > [http://heavywaterops.com](http://heavywaterops.com) | @heavywaterops
> > > > 
> > > > On Fri, Mar 6, 2015 at 2:29 PM, Michael Lindsay \<[mlindsay@metrodigi.com](mailto:mlindsay@metrodigi.com)
> > > > 
> > > > > wrote:
> > > > 
> > > > > Hi again Michael 🙂 I'm new to VPC, but I feel like I've poured over  
> > > > > all the settings there. Would the behavior be different with knife than  
> > > > > ssh on the same workstation in this regard?
> > > > > 
> > > > > On Fri, Mar 6, 2015 at 2:19 PM, Michael Weinberg [michael@hw-ops.com](mailto:michael@hw-ops.com)  
> > > > > wrote:
> > > > > 
> > > > > > Hi Michael,
> > > > > > 
> > > > > > I generally use Cloudformation for all my VPC instances, so have not  
> > > > > > attempted a direct bootstrap. Have you confirmed that the inbound and  
> > > > > > outbound security group and ACL rules allow traffic both directions on 22,  
> > > > > > 80, 443, and the ephemeral ports?
> > > > > > 
> > > > > > --  
> > > > > > _Michael F. Weinberg | Director of Operations_  
> > > > > > [http://heavywaterops.com](http://heavywaterops.com) | @heavywaterops
> > > > > > 
> > > > > > On Fri, Mar 6, 2015 at 2:16 PM, Michael Lindsay \<  
> > > > > > [mlindsay@metrodigi.com](mailto:mlindsay@metrodigi.com)\> wrote:
> > > > > > 
> > > > > > > Hello everyone…
> > > > > > > 
> > > > > > > I’m attempting my first knife ec2 create commands for building  
> > > > > > > instances inside a VPC.
> > > > > > > 
> > > > > > > The problem I'm facing is that "Waiting for sshd access to become  
> > > > > > > available...." Never completes. What's weird (and flies in the face of  
> > > > > > > what I thought was going on) is that while I'm watching little dots appear,  
> > > > > > > in another terminal window on the same workstation, using the same identity  
> > > > > > > file, user, and I think hostname (EIP) that the knife command is using, I  
> > > > > > > CAN ssh into the instance.  
> > > > > > > Any ideas what might cause this?
> > > > > > > 
> > > > > > > - Michael

---

<div class="post-metadata">

**Author:** ![Michael\_Lindsay](https://avatars.discourse-cdn.com/v4/letter/m/dec6dc/32.png) [@Michael\_Lindsay](https://discourse.chef.io/u/Michael_Lindsay)\
**Post date:** [March 6, 2015, 11:54pm UTC](https://discourse.chef.io/t/knife-ec2-failing-on-sshd/6380/10 "2015-03-06T23:54:17Z")

</div>

Things are definitely improving:

First attempt with this debug statement indicates that it's using the EID  
to connect, but got this: Net::SSH::HostKeyMismatch. Realized since I've  
been putting so many different instances behind this EID, I had to kill  
it's known\_hosts entry (shouldn't --no-host-key-verify be doing this for  
me?)

Now I'm getting "Authentication failed for user @[EIP].  
(Net::SSH::AuthenticationFailed)" Which appears to be missing the username.

This is the stack trace:

.../opt/chefdk/embedded/lib/ruby/gems/2.1.0/gems/net-ssh-2.9.2/lib/net/ssh.rb:224:in  
`start': Authentication failed for user @[EIP]  
(Net::SSH::AuthenticationFailed)

from  
/opt/chefdk/embedded/lib/ruby/gems/2.1.0/gems/net-ssh-gateway-1.2.0/lib/net/ssh/gateway.rb:74:in  
`initialize'

from  
/Users/mnl/.chefdk/gem/ruby/2.1.0/gems/knife-ec2-0.10.0/lib/chef/knife/ec2\_server\_create.rb:815:in  
`new'

from  
/Users/mnl/.chefdk/gem/ruby/2.1.0/gems/knife-ec2-0.10.0/lib/chef/knife/ec2\_server\_create.rb:815:in  
`configure\_ssh\_gateway'

from  
/Users/mnl/.chefdk/gem/ruby/2.1.0/gems/knife-ec2-0.10.0/lib/chef/knife/ec2\_server\_create.rb:779:in  
`tunnel\_test\_ssh'

from  
/Users/mnl/.chefdk/gem/ruby/2.1.0/gems/knife-ec2-0.10.0/lib/chef/knife/ec2\_server\_create.rb:766:in  
`wait\_for\_tunnelled\_sshd'

from  
/Users/mnl/.chefdk/gem/ruby/2.1.0/gems/knife-ec2-0.10.0/lib/chef/knife/ec2\_server\_create.rb:730:in  
`wait\_for\_sshd'

from  
/Users/mnl/.chefdk/gem/ruby/2.1.0/gems/knife-ec2-0.10.0/lib/chef/knife/ec2\_server\_create.rb:406:in  
`run'

from /opt/chefdk/embedded/apps/chef/lib/chef/knife.rb:417:in `block in  
run\_with\_pretty\_exceptions'

from /opt/chefdk/embedded/apps/chef/lib/chef/local\_mode.rb:38:in  
`with\_server\_connectivity'

from /opt/chefdk/embedded/apps/chef/lib/chef/knife.rb:416:in  
`run\_with\_pretty\_exceptions'

from /opt/chefdk/embedded/apps/chef/lib/chef/knife.rb:213:in `run'

from /opt/chefdk/embedded/apps/chef/lib/chef/application/knife.rb:139:in  
`run'

from /opt/chefdk/embedded/apps/chef/bin/knife:25:in `\<top (required)\>'

from /opt/chefdk/bin/knife:40:in `load'

from /opt/chefdk/bin/knife:40:in `'

On Fri, Mar 6, 2015 at 3:36 PM, Darren Dyke [dwdyke@gmail.com](mailto:dwdyke@gmail.com) wrote:

> @Michael L.
> 
> If you are using the --associate-eip flag, try setting  
> "--server-connect-attribute public\_ip\_address" See below from the ec2  
> server create:  
> [https://github.com/chef/knife-ec2/blob/master/lib/chef/knife/ec2\_server\_create.rb#L260-L264](https://github.com/chef/knife-ec2/blob/master/lib/chef/knife/ec2_server_create.rb#L260-L264)
> 
> option :server\_connect\_attribute, :long =\> "--server-connect-attribute  
> ATTRIBUTE", :short =\> "-a ATTRIBUTE", :description =\> "The EC2 server  
> attribute to use for SSH connection. Use this attr for creating VPC  
> instances along with --associate-eip", :default =\> nil
> 
> On Fri, Mar 6, 2015 at 6:19 PM, Michael Lindsay [mlindsay@metrodigi.com](mailto:mlindsay@metrodigi.com)  
> wrote:
> 
> > @Julian, it did find it's way to tcp\_test\_ssh after all. Running with  
> > Debug enabled I can see 'No ssh gateway found'. Furthermore I can see it  
> > is trying to connect to the Private IP Address and not the EIP that I  
> > provided. Which explains the difference between my ssh and knife's... Just  
> > looking for a fix for that now.
> > 
> > - M
> > 
> > On Fri, Mar 6, 2015 at 3:04 PM, Michael Lindsay [mlindsay@metrodigi.com](mailto:mlindsay@metrodigi.com)  
> > wrote:
> > 
> > > @Julian: hadn't thought to look at the source code, that's good info  
> > > (and I can see why the dots roll out more slowly 😉 ). I'm not connecting  
> > > to an ubuntu instance so looks like it wouldn't be TCP connection in the  
> > > second git file but instead something from here?
> > > 
> > > [https://github.com/chef/knife-ec2/blob/master/lib/chef/knife/ec2\_server\_create.rb#L748-L769](https://github.com/chef/knife-ec2/blob/master/lib/chef/knife/ec2_server_create.rb#L748-L769)
> > > 
> > > @Darren: It's a public subnet, so no proxy required
> > > 
> > > On Fri, Mar 6, 2015 at 2:48 PM, Darren Dyke [dwdyke@gmail.com](mailto:dwdyke@gmail.com) wrote:
> > > 
> > > > Hello, are you trying to configure a node on a private subnet? If so  
> > > > are you supplying the --ssh-gateway option/configure ssh config proxies?
> > > > 
> > > > On Fri, Mar 6, 2015 at 5:32 PM, Michael Weinberg [michael@hw-ops.com](mailto:michael@hw-ops.com)  
> > > > wrote:
> > > > 
> > > > > No, it shouldn't be. But I don't know what is actually happening  
> > > > > during 'waiting for sshd,' so on the off chance there's some additional  
> > > > > communication there I thought I'd suggest it.
> > > > > 
> > > > > --  
> > > > > _Michael F. Weinberg | Director of Operations_  
> > > > > [http://heavywaterops.com](http://heavywaterops.com) | @heavywaterops
> > > > > 
> > > > > On Fri, Mar 6, 2015 at 2:29 PM, Michael Lindsay \<  
> > > > > [mlindsay@metrodigi.com](mailto:mlindsay@metrodigi.com)\> wrote:
> > > > > 
> > > > > > Hi again Michael 🙂 I'm new to VPC, but I feel like I've poured over  
> > > > > > all the settings there. Would the behavior be different with knife than  
> > > > > > ssh on the same workstation in this regard?
> > > > > > 
> > > > > > On Fri, Mar 6, 2015 at 2:19 PM, Michael Weinberg [michael@hw-ops.com](mailto:michael@hw-ops.com)  
> > > > > > wrote:
> > > > > > 
> > > > > > > Hi Michael,
> > > > > > > 
> > > > > > > I generally use Cloudformation for all my VPC instances, so have not  
> > > > > > > attempted a direct bootstrap. Have you confirmed that the inbound and  
> > > > > > > outbound security group and ACL rules allow traffic both directions on 22,  
> > > > > > > 80, 443, and the ephemeral ports?
> > > > > > > 
> > > > > > > --  
> > > > > > > _Michael F. Weinberg | Director of Operations_  
> > > > > > > [http://heavywaterops.com](http://heavywaterops.com) | @heavywaterops
> > > > > > > 
> > > > > > > On Fri, Mar 6, 2015 at 2:16 PM, Michael Lindsay \<  
> > > > > > > [mlindsay@metrodigi.com](mailto:mlindsay@metrodigi.com)\> wrote:
> > > > > > > 
> > > > > > > > Hello everyone…
> > > > > > > > 
> > > > > > > > I’m attempting my first knife ec2 create commands for building  
> > > > > > > > instances inside a VPC.
> > > > > > > > 
> > > > > > > > The problem I'm facing is that "Waiting for sshd access to become  
> > > > > > > > available...." Never completes. What's weird (and flies in the face of  
> > > > > > > > what I thought was going on) is that while I'm watching little dots appear,  
> > > > > > > > in another terminal window on the same workstation, using the same identity  
> > > > > > > > file, user, and I think hostname (EIP) that the knife command is using, I  
> > > > > > > > CAN ssh into the instance.  
> > > > > > > > Any ideas what might cause this?
> > > > > > > > 
> > > > > > > > - Michael

---

<div class="post-metadata">

**Author:** ![Darren\_Dyke](https://sea2.discourse-cdn.com/flex016/user_avatar/discourse.chef.io/darren_dyke/32/165_2.png) [@Darren\_Dyke](https://discourse.chef.io/u/Darren_Dyke)\
**Post date:** [March 6, 2015, 11:57pm UTC](https://discourse.chef.io/t/knife-ec2-failing-on-sshd/6380/11 "2015-03-06T23:57:14Z")

</div>

Are you passing --ssh-user ?

On Fri, Mar 6, 2015 at 6:54 PM, Michael Lindsay [mlindsay@metrodigi.com](mailto:mlindsay@metrodigi.com)  
wrote:

> Things are definitely improving:
> 
> First attempt with this debug statement indicates that it's using the EID  
> to connect, but got this: Net::SSH::HostKeyMismatch. Realized since I've  
> been putting so many different instances behind this EID, I had to kill  
> it's known\_hosts entry (shouldn't --no-host-key-verify be doing this for  
> me?)
> 
> Now I'm getting "Authentication failed for user @[EIP].  
> (Net::SSH::AuthenticationFailed)" Which appears to be missing the username.
> 
> This is the stack trace:
> 
> .../opt/chefdk/embedded/lib/ruby/gems/2.1.0/gems/net-ssh-2.9.2/lib/net/ssh.rb:224:in  
> `start': Authentication failed for user @[EIP]  
> (Net::SSH::AuthenticationFailed)
> 
> from  
> /opt/chefdk/embedded/lib/ruby/gems/2.1.0/gems/net-ssh-gateway-1.2.0/lib/net/ssh/gateway.rb:74:in  
> `initialize'
> 
> from  
> /Users/mnl/.chefdk/gem/ruby/2.1.0/gems/knife-ec2-0.10.0/lib/chef/knife/ec2\_server\_create.rb:815:in  
> `new'
> 
> from  
> /Users/mnl/.chefdk/gem/ruby/2.1.0/gems/knife-ec2-0.10.0/lib/chef/knife/ec2\_server\_create.rb:815:in  
> `configure\_ssh\_gateway'
> 
> from  
> /Users/mnl/.chefdk/gem/ruby/2.1.0/gems/knife-ec2-0.10.0/lib/chef/knife/ec2\_server\_create.rb:779:in  
> `tunnel\_test\_ssh'
> 
> from  
> /Users/mnl/.chefdk/gem/ruby/2.1.0/gems/knife-ec2-0.10.0/lib/chef/knife/ec2\_server\_create.rb:766:in  
> `wait\_for\_tunnelled\_sshd'
> 
> from  
> /Users/mnl/.chefdk/gem/ruby/2.1.0/gems/knife-ec2-0.10.0/lib/chef/knife/ec2\_server\_create.rb:730:in  
> `wait\_for\_sshd'
> 
> from  
> /Users/mnl/.chefdk/gem/ruby/2.1.0/gems/knife-ec2-0.10.0/lib/chef/knife/ec2\_server\_create.rb:406:in  
> `run'
> 
> from /opt/chefdk/embedded/apps/chef/lib/chef/knife.rb:417:in `block in  
> run\_with\_pretty\_exceptions'
> 
> from /opt/chefdk/embedded/apps/chef/lib/chef/local\_mode.rb:38:in  
> `with\_server\_connectivity'
> 
> from /opt/chefdk/embedded/apps/chef/lib/chef/knife.rb:416:in  
> `run\_with\_pretty\_exceptions'
> 
> from /opt/chefdk/embedded/apps/chef/lib/chef/knife.rb:213:in `run'
> 
> from /opt/chefdk/embedded/apps/chef/lib/chef/application/knife.rb:139:in  
> `run'
> 
> from /opt/chefdk/embedded/apps/chef/bin/knife:25:in `\<top (required)\>'
> 
> from /opt/chefdk/bin/knife:40:in `load'
> 
> from /opt/chefdk/bin/knife:40:in `'
> 
> On Fri, Mar 6, 2015 at 3:36 PM, Darren Dyke [dwdyke@gmail.com](mailto:dwdyke@gmail.com) wrote:
> 
> > @Michael L.
> > 
> > If you are using the --associate-eip flag, try setting  
> > "--server-connect-attribute public\_ip\_address" See below from the ec2  
> > server create:  
> > [https://github.com/chef/knife-ec2/blob/master/lib/chef/knife/ec2\_server\_create.rb#L260-L264](https://github.com/chef/knife-ec2/blob/master/lib/chef/knife/ec2_server_create.rb#L260-L264)
> > 
> > option :server\_connect\_attribute, :long =\> "--server-connect-attribute  
> > ATTRIBUTE", :short =\> "-a ATTRIBUTE", :description =\> "The EC2 server  
> > attribute to use for SSH connection. Use this attr for creating VPC  
> > instances along with --associate-eip", :default =\> nil
> > 
> > On Fri, Mar 6, 2015 at 6:19 PM, Michael Lindsay [mlindsay@metrodigi.com](mailto:mlindsay@metrodigi.com)  
> > wrote:
> > 
> > > @Julian, it did find it's way to tcp\_test\_ssh after all. Running with  
> > > Debug enabled I can see 'No ssh gateway found'. Furthermore I can see it  
> > > is trying to connect to the Private IP Address and not the EIP that I  
> > > provided. Which explains the difference between my ssh and knife's... Just  
> > > looking for a fix for that now.
> > > 
> > > - M
> > > 
> > > On Fri, Mar 6, 2015 at 3:04 PM, Michael Lindsay [mlindsay@metrodigi.com](mailto:mlindsay@metrodigi.com)  
> > > wrote:
> > > 
> > > > @Julian: hadn't thought to look at the source code, that's good info  
> > > > (and I can see why the dots roll out more slowly 😉 ). I'm not connecting  
> > > > to an ubuntu instance so looks like it wouldn't be TCP connection in the  
> > > > second git file but instead something from here?
> > > > 
> > > > [https://github.com/chef/knife-ec2/blob/master/lib/chef/knife/ec2\_server\_create.rb#L748-L769](https://github.com/chef/knife-ec2/blob/master/lib/chef/knife/ec2_server_create.rb#L748-L769)
> > > > 
> > > > @Darren: It's a public subnet, so no proxy required
> > > > 
> > > > On Fri, Mar 6, 2015 at 2:48 PM, Darren Dyke [dwdyke@gmail.com](mailto:dwdyke@gmail.com) wrote:
> > > > 
> > > > > Hello, are you trying to configure a node on a private subnet? If so  
> > > > > are you supplying the --ssh-gateway option/configure ssh config proxies?
> > > > > 
> > > > > On Fri, Mar 6, 2015 at 5:32 PM, Michael Weinberg [michael@hw-ops.com](mailto:michael@hw-ops.com)  
> > > > > wrote:
> > > > > 
> > > > > > No, it shouldn't be. But I don't know what is actually happening  
> > > > > > during 'waiting for sshd,' so on the off chance there's some additional  
> > > > > > communication there I thought I'd suggest it.
> > > > > > 
> > > > > > --  
> > > > > > _Michael F. Weinberg | Director of Operations_  
> > > > > > [http://heavywaterops.com](http://heavywaterops.com) | @heavywaterops
> > > > > > 
> > > > > > On Fri, Mar 6, 2015 at 2:29 PM, Michael Lindsay \<  
> > > > > > [mlindsay@metrodigi.com](mailto:mlindsay@metrodigi.com)\> wrote:
> > > > > > 
> > > > > > > Hi again Michael 🙂 I'm new to VPC, but I feel like I've poured  
> > > > > > > over all the settings there. Would the behavior be different with knife  
> > > > > > > than ssh on the same workstation in this regard?
> > > > > > > 
> > > > > > > On Fri, Mar 6, 2015 at 2:19 PM, Michael Weinberg \<[michael@hw-ops.com](mailto:michael@hw-ops.com)
> > > > > > > 
> > > > > > > > wrote:
> > > > > > > 
> > > > > > > > Hi Michael,
> > > > > > > > 
> > > > > > > > I generally use Cloudformation for all my VPC instances, so have  
> > > > > > > > not attempted a direct bootstrap. Have you confirmed that the inbound and  
> > > > > > > > outbound security group and ACL rules allow traffic both directions on 22,  
> > > > > > > > 80, 443, and the ephemeral ports?
> > > > > > > > 
> > > > > > > > --  
> > > > > > > > _Michael F. Weinberg | Director of Operations_  
> > > > > > > > [http://heavywaterops.com](http://heavywaterops.com) | @heavywaterops
> > > > > > > > 
> > > > > > > > On Fri, Mar 6, 2015 at 2:16 PM, Michael Lindsay \<  
> > > > > > > > [mlindsay@metrodigi.com](mailto:mlindsay@metrodigi.com)\> wrote:
> > > > > > > > 
> > > > > > > > > Hello everyone…
> > > > > > > > > 
> > > > > > > > > I’m attempting my first knife ec2 create commands for building  
> > > > > > > > > instances inside a VPC.
> > > > > > > > > 
> > > > > > > > > The problem I'm facing is that "Waiting for sshd access to become  
> > > > > > > > > available...." Never completes. What's weird (and flies in the face of  
> > > > > > > > > what I thought was going on) is that while I'm watching little dots appear,  
> > > > > > > > > in another terminal window on the same workstation, using the same identity  
> > > > > > > > > file, user, and I think hostname (EIP) that the knife command is using, I  
> > > > > > > > > CAN ssh into the instance.  
> > > > > > > > > Any ideas what might cause this?
> > > > > > > > > 
> > > > > > > > > - Michael

---

<div class="post-metadata">

**Author:** ![Michael\_Lindsay](https://avatars.discourse-cdn.com/v4/letter/m/dec6dc/32.png) [@Michael\_Lindsay](https://discourse.chef.io/u/Michael_Lindsay)\
**Post date:** [March 7, 2015, 12:05am UTC](https://discourse.chef.io/t/knife-ec2-failing-on-sshd/6380/12 "2015-03-07T00:05:39Z")

</div>

I'd left --ssh-gateway [EID] in there from a previous experiment. Running  
without that appears to have fixed the problem. Opened up chef server's  
443 to the instance's security group and now I'm off and (very verbosely)  
running.

Thanks Darren & Michael!

On Fri, Mar 6, 2015 at 3:57 PM, Darren Dyke [dwdyke@gmail.com](mailto:dwdyke@gmail.com) wrote:

> Are you passing --ssh-user ?
> 
> On Fri, Mar 6, 2015 at 6:54 PM, Michael Lindsay [mlindsay@metrodigi.com](mailto:mlindsay@metrodigi.com)  
> wrote:
> 
> > Things are definitely improving:
> > 
> > First attempt with this debug statement indicates that it's using the EID  
> > to connect, but got this: Net::SSH::HostKeyMismatch. Realized since I've  
> > been putting so many different instances behind this EID, I had to kill  
> > it's known\_hosts entry (shouldn't --no-host-key-verify be doing this for  
> > me?)
> > 
> > Now I'm getting "Authentication failed for user @[EIP].  
> > (Net::SSH::AuthenticationFailed)" Which appears to be missing the username.
> > 
> > This is the stack trace:
> > 
> > .../opt/chefdk/embedded/lib/ruby/gems/2.1.0/gems/net-ssh-2.9.2/lib/net/ssh.rb:224:in  
> > `start': Authentication failed for user @[EIP]  
> > (Net::SSH::AuthenticationFailed)
> > 
> > from  
> > /opt/chefdk/embedded/lib/ruby/gems/2.1.0/gems/net-ssh-gateway-1.2.0/lib/net/ssh/gateway.rb:74:in  
> > `initialize'
> > 
> > from  
> > /Users/mnl/.chefdk/gem/ruby/2.1.0/gems/knife-ec2-0.10.0/lib/chef/knife/ec2\_server\_create.rb:815:in  
> > `new'
> > 
> > from  
> > /Users/mnl/.chefdk/gem/ruby/2.1.0/gems/knife-ec2-0.10.0/lib/chef/knife/ec2\_server\_create.rb:815:in  
> > `configure\_ssh\_gateway'
> > 
> > from  
> > /Users/mnl/.chefdk/gem/ruby/2.1.0/gems/knife-ec2-0.10.0/lib/chef/knife/ec2\_server\_create.rb:779:in  
> > `tunnel\_test\_ssh'
> > 
> > from  
> > /Users/mnl/.chefdk/gem/ruby/2.1.0/gems/knife-ec2-0.10.0/lib/chef/knife/ec2\_server\_create.rb:766:in  
> > `wait\_for\_tunnelled\_sshd'
> > 
> > from  
> > /Users/mnl/.chefdk/gem/ruby/2.1.0/gems/knife-ec2-0.10.0/lib/chef/knife/ec2\_server\_create.rb:730:in  
> > `wait\_for\_sshd'
> > 
> > from  
> > /Users/mnl/.chefdk/gem/ruby/2.1.0/gems/knife-ec2-0.10.0/lib/chef/knife/ec2\_server\_create.rb:406:in  
> > `run'
> > 
> > from /opt/chefdk/embedded/apps/chef/lib/chef/knife.rb:417:in `block in  
> > run\_with\_pretty\_exceptions'
> > 
> > from /opt/chefdk/embedded/apps/chef/lib/chef/local\_mode.rb:38:in  
> > `with\_server\_connectivity'
> > 
> > from /opt/chefdk/embedded/apps/chef/lib/chef/knife.rb:416:in  
> > `run\_with\_pretty\_exceptions'
> > 
> > from /opt/chefdk/embedded/apps/chef/lib/chef/knife.rb:213:in `run'
> > 
> > from /opt/chefdk/embedded/apps/chef/lib/chef/application/knife.rb:139:in  
> > `run'
> > 
> > from /opt/chefdk/embedded/apps/chef/bin/knife:25:in `\<top (required)\>'
> > 
> > from /opt/chefdk/bin/knife:40:in `load'
> > 
> > from /opt/chefdk/bin/knife:40:in `'
> > 
> > On Fri, Mar 6, 2015 at 3:36 PM, Darren Dyke [dwdyke@gmail.com](mailto:dwdyke@gmail.com) wrote:
> > 
> > > @Michael L.
> > > 
> > > If you are using the --associate-eip flag, try setting  
> > > "--server-connect-attribute public\_ip\_address" See below from the ec2  
> > > server create:  
> > > [https://github.com/chef/knife-ec2/blob/master/lib/chef/knife/ec2\_server\_create.rb#L260-L264](https://github.com/chef/knife-ec2/blob/master/lib/chef/knife/ec2_server_create.rb#L260-L264)
> > > 
> > > option :server\_connect\_attribute, :long =\> "--server-connect-attribute  
> > > ATTRIBUTE", :short =\> "-a ATTRIBUTE", :description =\> "The EC2 server  
> > > attribute to use for SSH connection. Use this attr for creating VPC  
> > > instances along with --associate-eip", :default =\> nil
> > > 
> > > On Fri, Mar 6, 2015 at 6:19 PM, Michael Lindsay [mlindsay@metrodigi.com](mailto:mlindsay@metrodigi.com)  
> > > wrote:
> > > 
> > > > @Julian, it did find it's way to tcp\_test\_ssh after all. Running with  
> > > > Debug enabled I can see 'No ssh gateway found'. Furthermore I can see it  
> > > > is trying to connect to the Private IP Address and not the EIP that I  
> > > > provided. Which explains the difference between my ssh and knife's... Just  
> > > > looking for a fix for that now.
> > > > 
> > > > - M
> > > > 
> > > > On Fri, Mar 6, 2015 at 3:04 PM, Michael Lindsay \<[mlindsay@metrodigi.com](mailto:mlindsay@metrodigi.com)
> > > > 
> > > > > wrote:
> > > > 
> > > > > @Julian: hadn't thought to look at the source code, that's good info  
> > > > > (and I can see why the dots roll out more slowly 😉 ). I'm not connecting  
> > > > > to an ubuntu instance so looks like it wouldn't be TCP connection in the  
> > > > > second git file but instead something from here?
> > > > > 
> > > > > [https://github.com/chef/knife-ec2/blob/master/lib/chef/knife/ec2\_server\_create.rb#L748-L769](https://github.com/chef/knife-ec2/blob/master/lib/chef/knife/ec2_server_create.rb#L748-L769)
> > > > > 
> > > > > @Darren: It's a public subnet, so no proxy required
> > > > > 
> > > > > On Fri, Mar 6, 2015 at 2:48 PM, Darren Dyke [dwdyke@gmail.com](mailto:dwdyke@gmail.com) wrote:
> > > > > 
> > > > > > Hello, are you trying to configure a node on a private subnet? If so  
> > > > > > are you supplying the --ssh-gateway option/configure ssh config proxies?
> > > > > > 
> > > > > > On Fri, Mar 6, 2015 at 5:32 PM, Michael Weinberg [michael@hw-ops.com](mailto:michael@hw-ops.com)  
> > > > > > wrote:
> > > > > > 
> > > > > > > No, it shouldn't be. But I don't know what is actually happening  
> > > > > > > during 'waiting for sshd,' so on the off chance there's some additional  
> > > > > > > communication there I thought I'd suggest it.
> > > > > > > 
> > > > > > > --  
> > > > > > > _Michael F. Weinberg | Director of Operations_  
> > > > > > > [http://heavywaterops.com](http://heavywaterops.com) | @heavywaterops
> > > > > > > 
> > > > > > > On Fri, Mar 6, 2015 at 2:29 PM, Michael Lindsay \<  
> > > > > > > [mlindsay@metrodigi.com](mailto:mlindsay@metrodigi.com)\> wrote:
> > > > > > > 
> > > > > > > > Hi again Michael 🙂 I'm new to VPC, but I feel like I've poured  
> > > > > > > > over all the settings there. Would the behavior be different with knife  
> > > > > > > > than ssh on the same workstation in this regard?
> > > > > > > > 
> > > > > > > > On Fri, Mar 6, 2015 at 2:19 PM, Michael Weinberg \<  
> > > > > > > > [michael@hw-ops.com](mailto:michael@hw-ops.com)\> wrote:
> > > > > > > > 
> > > > > > > > > Hi Michael,
> > > > > > > > > 
> > > > > > > > > I generally use Cloudformation for all my VPC instances, so have  
> > > > > > > > > not attempted a direct bootstrap. Have you confirmed that the inbound and  
> > > > > > > > > outbound security group and ACL rules allow traffic both directions on 22,  
> > > > > > > > > 80, 443, and the ephemeral ports?
> > > > > > > > > 
> > > > > > > > > --  
> > > > > > > > > _Michael F. Weinberg | Director of Operations_  
> > > > > > > > > [http://heavywaterops.com](http://heavywaterops.com) | @heavywaterops
> > > > > > > > > 
> > > > > > > > > On Fri, Mar 6, 2015 at 2:16 PM, Michael Lindsay \<  
> > > > > > > > > [mlindsay@metrodigi.com](mailto:mlindsay@metrodigi.com)\> wrote:
> > > > > > > > > 
> > > > > > > > > > Hello everyone…
> > > > > > > > > > 
> > > > > > > > > > I’m attempting my first knife ec2 create commands for building  
> > > > > > > > > > instances inside a VPC.
> > > > > > > > > > 
> > > > > > > > > > The problem I'm facing is that "Waiting for sshd access to become  
> > > > > > > > > > available...." Never completes. What's weird (and flies in the face of  
> > > > > > > > > > what I thought was going on) is that while I'm watching little dots appear,  
> > > > > > > > > > in another terminal window on the same workstation, using the same identity  
> > > > > > > > > > file, user, and I think hostname (EIP) that the knife command is using, I  
> > > > > > > > > > CAN ssh into the instance.  
> > > > > > > > > > Any ideas what might cause this?
> > > > > > > > > > 
> > > > > > > > > > - Michael

---

<div class="post-metadata">

**Author:** ![Darren\_Dyke](https://sea2.discourse-cdn.com/flex016/user_avatar/discourse.chef.io/darren_dyke/32/165_2.png) [@Darren\_Dyke](https://discourse.chef.io/u/Darren_Dyke)\
**Post date:** [March 7, 2015, 12:06am UTC](https://discourse.chef.io/t/knife-ec2-failing-on-sshd/6380/13 "2015-03-07T00:06:46Z")

</div>

Wicked man! Glad you got it working

On Fri, Mar 6, 2015 at 7:05 PM, Michael Lindsay [mlindsay@metrodigi.com](mailto:mlindsay@metrodigi.com)  
wrote:

> I'd left --ssh-gateway [EID] in there from a previous experiment. Running  
> without that appears to have fixed the problem. Opened up chef server's  
> 443 to the instance's security group and now I'm off and (very verbosely)  
> running.
> 
> Thanks Darren & Michael!
> 
> On Fri, Mar 6, 2015 at 3:57 PM, Darren Dyke [dwdyke@gmail.com](mailto:dwdyke@gmail.com) wrote:
> 
> > Are you passing --ssh-user ?
> > 
> > On Fri, Mar 6, 2015 at 6:54 PM, Michael Lindsay [mlindsay@metrodigi.com](mailto:mlindsay@metrodigi.com)  
> > wrote:
> > 
> > > Things are definitely improving:
> > > 
> > > First attempt with this debug statement indicates that it's using the  
> > > EID to connect, but got this: Net::SSH::HostKeyMismatch. Realized since  
> > > I've been putting so many different instances behind this EID, I had to  
> > > kill it's known\_hosts entry (shouldn't --no-host-key-verify be doing this  
> > > for me?)
> > > 
> > > Now I'm getting "Authentication failed for user @[EIP].  
> > > (Net::SSH::AuthenticationFailed)" Which appears to be missing the username.
> > > 
> > > This is the stack trace:
> > > 
> > > .../opt/chefdk/embedded/lib/ruby/gems/2.1.0/gems/net-ssh-2.9.2/lib/net/ssh.rb:224:in  
> > > `start': Authentication failed for user @[EIP]  
> > > (Net::SSH::AuthenticationFailed)
> > > 
> > > from  
> > > /opt/chefdk/embedded/lib/ruby/gems/2.1.0/gems/net-ssh-gateway-1.2.0/lib/net/ssh/gateway.rb:74:in  
> > > `initialize'
> > > 
> > > from  
> > > /Users/mnl/.chefdk/gem/ruby/2.1.0/gems/knife-ec2-0.10.0/lib/chef/knife/ec2\_server\_create.rb:815:in  
> > > `new'
> > > 
> > > from  
> > > /Users/mnl/.chefdk/gem/ruby/2.1.0/gems/knife-ec2-0.10.0/lib/chef/knife/ec2\_server\_create.rb:815:in  
> > > `configure\_ssh\_gateway'
> > > 
> > > from  
> > > /Users/mnl/.chefdk/gem/ruby/2.1.0/gems/knife-ec2-0.10.0/lib/chef/knife/ec2\_server\_create.rb:779:in  
> > > `tunnel\_test\_ssh'
> > > 
> > > from  
> > > /Users/mnl/.chefdk/gem/ruby/2.1.0/gems/knife-ec2-0.10.0/lib/chef/knife/ec2\_server\_create.rb:766:in  
> > > `wait\_for\_tunnelled\_sshd'
> > > 
> > > from  
> > > /Users/mnl/.chefdk/gem/ruby/2.1.0/gems/knife-ec2-0.10.0/lib/chef/knife/ec2\_server\_create.rb:730:in  
> > > `wait\_for\_sshd'
> > > 
> > > from  
> > > /Users/mnl/.chefdk/gem/ruby/2.1.0/gems/knife-ec2-0.10.0/lib/chef/knife/ec2\_server\_create.rb:406:in  
> > > `run'
> > > 
> > > from /opt/chefdk/embedded/apps/chef/lib/chef/knife.rb:417:in `block in  
> > > run\_with\_pretty\_exceptions'
> > > 
> > > from /opt/chefdk/embedded/apps/chef/lib/chef/local\_mode.rb:38:in  
> > > `with\_server\_connectivity'
> > > 
> > > from /opt/chefdk/embedded/apps/chef/lib/chef/knife.rb:416:in  
> > > `run\_with\_pretty\_exceptions'
> > > 
> > > from /opt/chefdk/embedded/apps/chef/lib/chef/knife.rb:213:in `run'
> > > 
> > > from /opt/chefdk/embedded/apps/chef/lib/chef/application/knife.rb:139:in  
> > > `run'
> > > 
> > > from /opt/chefdk/embedded/apps/chef/bin/knife:25:in `\<top (required)\>'
> > > 
> > > from /opt/chefdk/bin/knife:40:in `load'
> > > 
> > > from /opt/chefdk/bin/knife:40:in `'
> > > 
> > > On Fri, Mar 6, 2015 at 3:36 PM, Darren Dyke [dwdyke@gmail.com](mailto:dwdyke@gmail.com) wrote:
> > > 
> > > > @Michael L.
> > > > 
> > > > If you are using the --associate-eip flag, try setting  
> > > > "--server-connect-attribute public\_ip\_address" See below from the ec2  
> > > > server create:  
> > > > [https://github.com/chef/knife-ec2/blob/master/lib/chef/knife/ec2\_server\_create.rb#L260-L264](https://github.com/chef/knife-ec2/blob/master/lib/chef/knife/ec2_server_create.rb#L260-L264)
> > > > 
> > > > option :server\_connect\_attribute, :long =\> "--server-connect-attribute  
> > > > ATTRIBUTE", :short =\> "-a ATTRIBUTE", :description =\> "The EC2 server  
> > > > attribute to use for SSH connection. Use this attr for creating VPC  
> > > > instances along with --associate-eip", :default =\> nil
> > > > 
> > > > On Fri, Mar 6, 2015 at 6:19 PM, Michael Lindsay \<[mlindsay@metrodigi.com](mailto:mlindsay@metrodigi.com)
> > > > 
> > > > > wrote:
> > > > 
> > > > > @Julian, it did find it's way to tcp\_test\_ssh after all. Running  
> > > > > with Debug enabled I can see 'No ssh gateway found'. Furthermore I can see  
> > > > > it is trying to connect to the Private IP Address and not the EIP that I  
> > > > > provided. Which explains the difference between my ssh and knife's... Just  
> > > > > looking for a fix for that now.
> > > > > 
> > > > > - M
> > > > > 
> > > > > On Fri, Mar 6, 2015 at 3:04 PM, Michael Lindsay \<  
> > > > > [mlindsay@metrodigi.com](mailto:mlindsay@metrodigi.com)\> wrote:
> > > > > 
> > > > > > @Julian: hadn't thought to look at the source code, that's good info  
> > > > > > (and I can see why the dots roll out more slowly 😉 ). I'm not connecting  
> > > > > > to an ubuntu instance so looks like it wouldn't be TCP connection in the  
> > > > > > second git file but instead something from here?
> > > > > > 
> > > > > > [https://github.com/chef/knife-ec2/blob/master/lib/chef/knife/ec2\_server\_create.rb#L748-L769](https://github.com/chef/knife-ec2/blob/master/lib/chef/knife/ec2_server_create.rb#L748-L769)
> > > > > > 
> > > > > > @Darren: It's a public subnet, so no proxy required
> > > > > > 
> > > > > > On Fri, Mar 6, 2015 at 2:48 PM, Darren Dyke [dwdyke@gmail.com](mailto:dwdyke@gmail.com) wrote:
> > > > > > 
> > > > > > > Hello, are you trying to configure a node on a private subnet? If so  
> > > > > > > are you supplying the --ssh-gateway option/configure ssh config proxies?
> > > > > > > 
> > > > > > > On Fri, Mar 6, 2015 at 5:32 PM, Michael Weinberg \<[michael@hw-ops.com](mailto:michael@hw-ops.com)
> > > > > > > 
> > > > > > > > wrote:
> > > > > > > 
> > > > > > > > No, it shouldn't be. But I don't know what is actually happening  
> > > > > > > > during 'waiting for sshd,' so on the off chance there's some additional  
> > > > > > > > communication there I thought I'd suggest it.
> > > > > > > > 
> > > > > > > > --  
> > > > > > > > _Michael F. Weinberg | Director of Operations_  
> > > > > > > > [http://heavywaterops.com](http://heavywaterops.com) | @heavywaterops
> > > > > > > > 
> > > > > > > > On Fri, Mar 6, 2015 at 2:29 PM, Michael Lindsay \<  
> > > > > > > > [mlindsay@metrodigi.com](mailto:mlindsay@metrodigi.com)\> wrote:
> > > > > > > > 
> > > > > > > > > Hi again Michael 🙂 I'm new to VPC, but I feel like I've poured  
> > > > > > > > > over all the settings there. Would the behavior be different with knife  
> > > > > > > > > than ssh on the same workstation in this regard?
> > > > > > > > > 
> > > > > > > > > On Fri, Mar 6, 2015 at 2:19 PM, Michael Weinberg \<  
> > > > > > > > > [michael@hw-ops.com](mailto:michael@hw-ops.com)\> wrote:
> > > > > > > > > 
> > > > > > > > > > Hi Michael,
> > > > > > > > > > 
> > > > > > > > > > I generally use Cloudformation for all my VPC instances, so have  
> > > > > > > > > > not attempted a direct bootstrap. Have you confirmed that the inbound and  
> > > > > > > > > > outbound security group and ACL rules allow traffic both directions on 22,  
> > > > > > > > > > 80, 443, and the ephemeral ports?
> > > > > > > > > > 
> > > > > > > > > > --  
> > > > > > > > > > _Michael F. Weinberg | Director of Operations_  
> > > > > > > > > > [http://heavywaterops.com](http://heavywaterops.com) | @heavywaterops
> > > > > > > > > > 
> > > > > > > > > > On Fri, Mar 6, 2015 at 2:16 PM, Michael Lindsay \<  
> > > > > > > > > > [mlindsay@metrodigi.com](mailto:mlindsay@metrodigi.com)\> wrote:
> > > > > > > > > > 
> > > > > > > > > > > Hello everyone…
> > > > > > > > > > > 
> > > > > > > > > > > I’m attempting my first knife ec2 create commands for building  
> > > > > > > > > > > instances inside a VPC.
> > > > > > > > > > > 
> > > > > > > > > > > The problem I'm facing is that "Waiting for sshd access to  
> > > > > > > > > > > become available...." Never completes. What's weird (and flies in the face  
> > > > > > > > > > > of what I thought was going on) is that while I'm watching little dots  
> > > > > > > > > > > appear, in another terminal window on the same workstation, using the same  
> > > > > > > > > > > identity file, user, and I think hostname (EIP) that the knife command is  
> > > > > > > > > > > using, I CAN ssh into the instance.  
> > > > > > > > > > > Any ideas what might cause this?
> > > > > > > > > > > 
> > > > > > > > > > > - Michael
