3des cipher and DH group size

Damien Miller djm at mindrot.org
Fri Feb 14 11:10:17 EST 2014


On Thu, 13 Feb 2014, Scott Neugroschl wrote:

> >Hubert Kario <hkario <at> redhat.com> writes:
> >
> >> [SNIP]
> >
> >3. OpenSSH primitives should be confined to ensure interoperability
> >   with implementations that are RFC non-compliant (e.g. cryptlib &
> >   DH GEX & RFC 4419).
> >
> >What's the point of standards then?
>
> Maybe a ssh_config option for DH GEX group size, so that people like
> Hubert can configure SSH such implementations?

You can do this now by editing /etc/ssh/moduli

Also KexAlgorithms=diffie-hellman-group14-sha1

-d


More information about the openssh-unix-dev mailing list