[Bug 2302] with DH-GEX, ssh (and sshd) should not fall back to unconfigured DH groups or at least document this behaviour and use a stronger group

bugzilla-daemon at mindrot.org bugzilla-daemon at mindrot.org
Wed May 27 10:13:11 AEST 2015


https://bugzilla.mindrot.org/show_bug.cgi?id=2302

--- Comment #6 from Damien Miller <djm at mindrot.org> ---
(In reply to Darren Tucker from comment #5)
> (In reply to Damien Miller from comment #4)
> > Comment on attachment 2630 [details]
> > Make the DH-GEX fallback group 4k bit.
> > 
> > Where did this group come from?
> 
> I generated it.  I pulled it off the file being prepared for the
> next moduli update.
> 
> > IMO it would be best to use one of
> > the standard groups if we're picking another fixed one - logjam
> > attacks aren't remotely plausible at this length, and doing so
> > avoids any questions over the group's provenance.
> 
> Presumably someone said something similar about group1 and group14
> at one point?

Attacks on group 1 are barely plausible now (taking over 45M core years
for the precomputation), group14 seems well beyond reach. Check the
table on pg.8 of the logjam paper.

-- 
You are receiving this mail because:
You are watching the assignee of the bug.
You are watching someone on the CC list of the bug.


More information about the openssh-bugs mailing list