[Bug 2302] with DH-GEX, ssh (and sshd) should not fall back to unconfigured DH groups or at least document this behaviour and use a stronger group
bugzilla-daemon at mindrot.org
bugzilla-daemon at mindrot.org
Tue May 26 19:40:21 AEST 2015
https://bugzilla.mindrot.org/show_bug.cgi?id=2302
--- Comment #4 from Damien Miller <djm at mindrot.org> ---
Comment on attachment 2630
--> https://bugzilla.mindrot.org/attachment.cgi?id=2630
Make the DH-GEX fallback group 4k bit.
Where did this group come from? IMO it would be best to use one of the
standard groups if we're picking another fixed one - logjam attacks
aren't remotely plausible at this length, and doing so avoids any
questions over the group's provenance.
You could use the RFC3526 (ISAKMP) 4096-bit group:
https://tools.ietf.org/html/rfc3526#page-5
--
You are receiving this mail because:
You are watching someone on the CC list of the bug.
You are watching the assignee of the bug.
More information about the openssh-bugs
mailing list