Mar 17 09:29:50 prd-ubuntu2204-docker-4c-4g-500054 passwd[688]: password for 'ubuntu' changed by 'root' Mar 17 09:29:50 prd-ubuntu2204-docker-4c-4g-500054 sshd[761]: Server listening on 0.0.0.0 port 22. Mar 17 09:29:50 prd-ubuntu2204-docker-4c-4g-500054 sshd[761]: Server listening on :: port 22. Mar 17 09:29:50 prd-ubuntu2204-docker-4c-4g-500054 systemd-logind[721]: New seat seat0. Mar 17 09:29:50 prd-ubuntu2204-docker-4c-4g-500054 systemd-logind[721]: Watching system buttons on /dev/input/event0 (Power Button) Mar 17 09:29:50 prd-ubuntu2204-docker-4c-4g-500054 systemd-logind[721]: Watching system buttons on /dev/input/event1 (AT Translated Set 2 keyboard) Mar 17 09:29:54 prd-ubuntu2204-docker-4c-4g-500054 sshd[969]: error: kex_exchange_identification: Connection closed by remote host Mar 17 09:29:54 prd-ubuntu2204-docker-4c-4g-500054 sshd[969]: Connection closed by 10.30.168.15 port 53916 Mar 17 09:30:00 prd-ubuntu2204-docker-4c-4g-500054 sshd[976]: Invalid user jenkins from 10.30.168.15 port 53932 Mar 17 09:30:00 prd-ubuntu2204-docker-4c-4g-500054 sshd[976]: userauth_pubkey: key type ssh-rsa not in PubkeyAcceptedAlgorithms [preauth] Mar 17 09:30:00 prd-ubuntu2204-docker-4c-4g-500054 sshd[976]: Received disconnect from 10.30.168.15 port 53932:11: Closed due to user request. [preauth] Mar 17 09:30:00 prd-ubuntu2204-docker-4c-4g-500054 sshd[976]: Disconnected from invalid user jenkins 10.30.168.15 port 53932 [preauth] Mar 17 09:30:01 prd-ubuntu2204-docker-4c-4g-500054 CRON[980]: pam_unix(cron:session): session opened for user root(uid=0) by (uid=0) Mar 17 09:30:01 prd-ubuntu2204-docker-4c-4g-500054 CRON[980]: pam_unix(cron:session): session closed for user root Mar 17 09:30:03 prd-ubuntu2204-docker-4c-4g-500054 sshd[983]: Invalid user jenkins from 10.30.168.15 port 53944 Mar 17 09:30:03 prd-ubuntu2204-docker-4c-4g-500054 sshd[983]: userauth_pubkey: key type ssh-rsa not in PubkeyAcceptedAlgorithms [preauth] Mar 17 09:30:03 prd-ubuntu2204-docker-4c-4g-500054 sshd[983]: Received disconnect from 10.30.168.15 port 53944:11: Closed due to user request. [preauth] Mar 17 09:30:03 prd-ubuntu2204-docker-4c-4g-500054 sshd[983]: Disconnected from invalid user jenkins 10.30.168.15 port 53944 [preauth] Mar 17 09:30:06 prd-ubuntu2204-docker-4c-4g-500054 sshd[985]: Invalid user jenkins from 10.30.168.15 port 53948 Mar 17 09:30:06 prd-ubuntu2204-docker-4c-4g-500054 sshd[985]: userauth_pubkey: key type ssh-rsa not in PubkeyAcceptedAlgorithms [preauth] Mar 17 09:30:06 prd-ubuntu2204-docker-4c-4g-500054 sshd[985]: Received disconnect from 10.30.168.15 port 53948:11: Closed due to user request. [preauth] Mar 17 09:30:06 prd-ubuntu2204-docker-4c-4g-500054 sshd[985]: Disconnected from invalid user jenkins 10.30.168.15 port 53948 [preauth] Mar 17 09:30:10 prd-ubuntu2204-docker-4c-4g-500054 sshd[1200]: Invalid user jenkins from 10.30.168.15 port 53958 Mar 17 09:30:10 prd-ubuntu2204-docker-4c-4g-500054 sshd[1200]: userauth_pubkey: key type ssh-rsa not in PubkeyAcceptedAlgorithms [preauth] Mar 17 09:30:10 prd-ubuntu2204-docker-4c-4g-500054 sshd[1200]: Received disconnect from 10.30.168.15 port 53958:11: Closed due to user request. [preauth] Mar 17 09:30:10 prd-ubuntu2204-docker-4c-4g-500054 sshd[1200]: Disconnected from invalid user jenkins 10.30.168.15 port 53958 [preauth] Mar 17 09:30:13 prd-ubuntu2204-docker-4c-4g-500054 sshd[1314]: Invalid user jenkins from 10.30.168.15 port 53968 Mar 17 09:30:13 prd-ubuntu2204-docker-4c-4g-500054 sshd[1314]: userauth_pubkey: key type ssh-rsa not in PubkeyAcceptedAlgorithms [preauth] Mar 17 09:30:13 prd-ubuntu2204-docker-4c-4g-500054 sshd[1314]: Received disconnect from 10.30.168.15 port 53968:11: Closed due to user request. [preauth] Mar 17 09:30:13 prd-ubuntu2204-docker-4c-4g-500054 sshd[1314]: Disconnected from invalid user jenkins 10.30.168.15 port 53968 [preauth] Mar 17 09:30:16 prd-ubuntu2204-docker-4c-4g-500054 useradd[1359]: new group: name=jenkins, GID=1001 Mar 17 09:30:16 prd-ubuntu2204-docker-4c-4g-500054 useradd[1359]: new user: name=jenkins, UID=1001, GID=1001, home=/home/jenkins, shell=/bin/bash, from=none Mar 17 09:30:16 prd-ubuntu2204-docker-4c-4g-500054 sshd[1352]: Invalid user jenkins from 10.30.168.15 port 53972 Mar 17 09:30:16 prd-ubuntu2204-docker-4c-4g-500054 usermod[1368]: add 'jenkins' to group 'docker' Mar 17 09:30:16 prd-ubuntu2204-docker-4c-4g-500054 usermod[1368]: add 'jenkins' to shadow group 'docker' Mar 17 09:30:16 prd-ubuntu2204-docker-4c-4g-500054 sshd[1352]: userauth_pubkey: key type ssh-rsa not in PubkeyAcceptedAlgorithms [preauth] Mar 17 09:30:16 prd-ubuntu2204-docker-4c-4g-500054 sshd[1352]: Received disconnect from 10.30.168.15 port 53972:11: Closed due to user request. [preauth] Mar 17 09:30:16 prd-ubuntu2204-docker-4c-4g-500054 sshd[1352]: Disconnected from invalid user jenkins 10.30.168.15 port 53972 [preauth] Mar 17 09:30:19 prd-ubuntu2204-docker-4c-4g-500054 sshd[1402]: Accepted publickey for jenkins from 10.30.168.15 port 53976 ssh2: RSA SHA256:BBsm4mRgG5V0fGum4Y1Rmy/vs16stdRVhwvexlLUhUs Mar 17 09:30:19 prd-ubuntu2204-docker-4c-4g-500054 sshd[1402]: pam_unix(sshd:session): session opened for user jenkins(uid=1001) by (uid=0) Mar 17 09:30:19 prd-ubuntu2204-docker-4c-4g-500054 systemd-logind[721]: New session 2 of user jenkins. Mar 17 09:30:19 prd-ubuntu2204-docker-4c-4g-500054 systemd: pam_unix(systemd-user:session): session opened for user jenkins(uid=1001) by (uid=0) Mar 17 09:31:02 prd-ubuntu2204-docker-4c-4g-500054 CRON[1892]: pam_unix(cron:session): session opened for user root(uid=0) by (uid=0) Mar 17 09:31:02 prd-ubuntu2204-docker-4c-4g-500054 CRON[1892]: pam_unix(cron:session): session closed for user root Mar 17 09:32:01 prd-ubuntu2204-docker-4c-4g-500054 CRON[2460]: pam_unix(cron:session): session opened for user root(uid=0) by (uid=0) Mar 17 09:32:01 prd-ubuntu2204-docker-4c-4g-500054 CRON[2460]: pam_unix(cron:session): session closed for user root Mar 17 09:32:53 prd-ubuntu2204-docker-4c-4g-500054 sudo: jenkins : PWD=/w/workspace/distribution-tox-verify-titanium ; USER=root ; COMMAND=/usr/bin/cp /var/log/auth.log /tmp Mar 17 09:32:53 prd-ubuntu2204-docker-4c-4g-500054 sudo: pam_unix(sudo:session): session opened for user root(uid=0) by (uid=1001)