[openssh-commits] [openssh] branch master updated (c07ea2180 -> 87f0cd189)
git+noreply at mindrot.org
git+noreply at mindrot.org
Thu Oct 1 17:28:44 AEST 2026
This is an automated email from the git hooks/post-receive script.
djm pushed a change to branch master
in repository openssh.
from c07ea2180 upstream: sftp: be stricter in accepting paths returned by the
new 39b9bd1cb upstream: fix the bit length of ML-DSA 44/Ed25519 keys that was
new f938c78d4 upstream: Implement a maximum number of KDF rounds that will be
new 88fe0b074 upstream: mention default KDF rounds is now 32
new 87f0cd189 upstream: start process of deprecating the -R flag. This was the
The 4 revisions listed above as "new" are entirely new to this
repository and will be described in separate emails. The revisions
listed as "add" were already present in the repository and have only
been added to this reference.
Detailed log of new commits:
commit 87f0cd1892e501f835dd210abea5461807c8deba
Author: djm at openbsd.org <djm at openbsd.org>
Date: Thu Oct 1 07:10:56 2026 +0000
upstream: start process of deprecating the -R flag. This was the
old way of performing a remote-to-remote copy that was basically executed scp
on the remote host. It barely worked (needing agent forwarding enabled or
usable credentials on the remote host) and has largely been replaced by a
better SFTP-protocol remote-to-remote copy that runs through the host
performing the copy.
We'll disable this option in a release or two; ok dtucker@
OpenBSD-Commit-ID: dc273300651e581c3db18edf21f2b05ceac60fd7
commit 88fe0b074ee0c0cdf6d87f8b86b4c959e7d2bdbc
Author: djm at openbsd.org <djm at openbsd.org>
Date: Thu Oct 1 07:08:05 2026 +0000
upstream: mention default KDF rounds is now 32
OpenBSD-Commit-ID: 0d17bf0ad02c8c0d897d9d01d1e4eb0f65ea749c
commit f938c78d490cb7556aa8ca1625e9b9bd1f963ed3
Author: djm at openbsd.org <djm at openbsd.org>
Date: Thu Oct 1 07:07:49 2026 +0000
upstream: Implement a maximum number of KDF rounds that will be
accepted when writing an OpenSSH-format private key or when loading one. This
limit is set pretty high (1<<20), but ensures that a service that is passed a
bad key with an ridiculously high number of rounds will _eventually_ complete
parsing it.
Also bump the default number of KDF rounds from 24 to 32 (this is a
linear increase, not like bcrypt(3) which is exponential).
Pointed out by Aris Adamantiadis
OpenBSD-Commit-ID: 843ff37b066b2879f4579a784e42a3c9d22b2ddc
commit 39b9bd1cb7d32428842c67e7e8b217027c16962b
Author: djm at openbsd.org <djm at openbsd.org>
Date: Thu Oct 1 04:17:39 2026 +0000
upstream: fix the bit length of ML-DSA 44/Ed25519 keys that was
being incorrectly reported as 256. The private key length for these composite
keys is 512 bits. This value is only used for display.
Spotted by Yiyue Wang
OpenBSD-Commit-ID: 5ba7c8a9a457434ca0652042e1c5940bbc6ef5e0
Summary of changes:
scp.c | 4 +++-
ssh-keygen.1 | 6 +++---
ssh-mldsa-eddsa.c | 6 +++---
sshkey.c | 13 +++++++++++--
4 files changed, 20 insertions(+), 9 deletions(-)
--
To stop receiving notification emails like this one, please contact
djm at mindrot.org.
More information about the openssh-commits
mailing list