# Mac OSX 12.4 client issue

**URL:** <https://community.thinlinc.com/t/mac-osx-12-4-client-issue/413>\
**Category:** Community Support\
**Tags:** rhel, ssh\
**Created:** [2 August 2022 02:33 UTC](https://community.thinlinc.com/t/mac-osx-12-4-client-issue/413 "2022-08-02T02:33:59Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![ashum](https://avatars.discourse-cdn.com/v4/letter/a/bbe5ce/32.png) [@ashum](https://community.thinlinc.com/u/ashum)\
**Post date:** [2 August 2022 02:33 UTC](https://community.thinlinc.com/t/mac-osx-12-4-client-issue/413/1 "2022-08-02T02:33:59Z")

</div>

Hi everyone,  
I am trying to connect to my Roccky Linux 9 server using client on my Mac.  
I get "Could not setup secure tunnel " issue. The port on mac is free. The agent is running. I can access through the browser no problem  
Did anyone have a similar issue?  
Any help appriciated.

---

<div class="post-metadata">

**Author:** ![martin](https://dub1.discourse-cdn.com/flex005/user_avatar/community.thinlinc.com/martin/32/41_2.png) [@martin](https://community.thinlinc.com/u/martin)\
**Post date:** [2 August 2022 06:29 UTC](https://community.thinlinc.com/t/mac-osx-12-4-client-issue/413/2 "2022-08-02T06:29:30Z")

</div>

Hello @ashum!

This error usually means that the client is unable to connect to the ssh  
daemon running on the machine hosting the vsmserver service. Please verify that you have OpenSSH server installed and necessary [ports open](https://www.cendio.com/resources/docs/tag/tcp-ports_server.html) on your Rocky Linux server.

Kind regards,  
Martin

---

<div class="post-metadata">

**Author:** ![ashum](https://avatars.discourse-cdn.com/v4/letter/a/bbe5ce/32.png) [@ashum](https://community.thinlinc.com/u/ashum)\
**Post date:** [2 August 2022 15:31 UTC](https://community.thinlinc.com/t/mac-osx-12-4-client-issue/413/3 "2022-08-02T15:31:57Z")

</div>

hmm,  
openssh-server is intalled  
the nmap is showing:

Host is up (0.00011s latency).

PORT STATE SERVICE  
22/tcp open ssh

---

<div class="post-metadata">

**Author:** ![ashum](https://avatars.discourse-cdn.com/v4/letter/a/bbe5ce/32.png) [@ashum](https://community.thinlinc.com/u/ashum)\
**Post date:** [2 August 2022 18:53 UTC](https://community.thinlinc.com/t/mac-osx-12-4-client-issue/413/4 "2022-08-02T18:53:54Z")

</div>

I can ssh to the machine no problem from the terminal

---

<div class="post-metadata">

**Author:** ![ashum](https://avatars.discourse-cdn.com/v4/letter/a/bbe5ce/32.png) [@ashum](https://community.thinlinc.com/u/ashum)\
**Post date:** [2 August 2022 23:25 UTC](https://community.thinlinc.com/t/mac-osx-12-4-client-issue/413/5 "2022-08-02T23:25:20Z")

</div>

not sure if its of any use but it looks like the agent is listening to port 904 for some reason

sudo grep listen /opt/thinlinc/etc/conf.d/\*

/opt/thinlinc/etc/conf.d/tlwebadm.hconf:listen\_port=1010

/opt/thinlinc/etc/conf.d/vsmagent.hconf:# Port to listen on

/opt/thinlinc/etc/conf.d/vsmagent.hconf:listen\_port=904

/opt/thinlinc/etc/conf.d/vsmserver.hconf:# Port to listen on

/opt/thinlinc/etc/conf.d/vsmserver.hconf:listen\_port=9000

/opt/thinlinc/etc/conf.d/webaccess.hconf:listen\_port=300

---

<div class="post-metadata">

**Author:** ![ashum](https://avatars.discourse-cdn.com/v4/letter/a/bbe5ce/32.png) [@ashum](https://community.thinlinc.com/u/ashum)\
**Post date:** [3 August 2022 01:06 UTC](https://community.thinlinc.com/t/mac-osx-12-4-client-issue/413/6 "2022-08-03T01:06:57Z")

</div>

I continued investigation and found that the when client attempt to connect it connects successfully to the running sshd server and then dropped out with error:

fatal: mm\_answer\_sign: sign: error in libcrypto

---

<div class="post-metadata">

**Author:** ![martin](https://dub1.discourse-cdn.com/flex005/user_avatar/community.thinlinc.com/martin/32/41_2.png) [@martin](https://community.thinlinc.com/u/martin)\
**Post date:** [3 August 2022 06:04 UTC](https://community.thinlinc.com/t/mac-osx-12-4-client-issue/413/7 "2022-08-03T06:04:05Z")

</div>

Hello @ashum

Ok, looks like you’ve stumbled upon this [bug](https://bugzilla.redhat.com/show_bug.cgi?id=2088750) for which we have a [Platform Specific Note](https://www.cendio.com/thinlinc/docs/platforms/redhat) with different known workarounds.

I believe the best way forward for you is to relax your system crypty policy to allow SHA-1, like so:

```auto
$ sudo update-crypto-policies --set DEFAULT:SHA1
$ sudo reboot

```

Regards,  
Martin

---

<div class="post-metadata">

**Author:** ![ashum](https://avatars.discourse-cdn.com/v4/letter/a/bbe5ce/32.png) [@ashum](https://community.thinlinc.com/u/ashum)\
**Post date:** [3 August 2022 13:28 UTC](https://community.thinlinc.com/t/mac-osx-12-4-client-issue/413/8 "2022-08-03T13:28:49Z")

</div>

That did the trick. Thx a ton.
