[Bug 1242] GSSAPI Keyexchange support

bugzilla-daemon at bugzilla.mindrot.org bugzilla-daemon at bugzilla.mindrot.org
Wed Feb 10 09:49:27 EST 2010


https://bugzilla.mindrot.org/show_bug.cgi?id=1242

Damien Miller <djm at mindrot.org> changed:

           What    |Removed                     |Added
----------------------------------------------------------------------------
             Status|NEW                         |RESOLVED
         Resolution|                            |WONTFIX

--- Comment #7 from Damien Miller <djm at mindrot.org> 2010-02-10 09:49:24 EST ---
None of the OpenSSH developers are in favour of adding this, and this
situation has not changed for several years. This is not a slight on
Simon's patch, which is of fine quality, but just that a) we don't
trust GSSAPI implementations that much and b) we don't like adding new
KEX since they are pre-auth attack surface. This one is particularly
scary, since it requires hooks out to typically root-owned system
resources.

-- 
Configure bugmail: https://bugzilla.mindrot.org/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are watching the assignee of the bug.
You are watching someone on the CC list of the bug.


More information about the openssh-bugs mailing list