[Bug 2302] with DH-GEX, ssh (and sshd) should not fall back to unconfigured DH groups or at least document this behaviour and use a stronger group
Darren Tucker
dtucker at zip.com.au
Fri Jul 10 20:06:52 AEST 2015
On Fri, Jul 10, 2015 at 8:01 PM, aixtools <aixtools at gmail.com> wrote:
> On 2015-06-02 5:31 AM, bugzilla-daemon at mindrot.org wrote:
[...]
> Do any such clients actually exist? RFC4419 says DH-GEX
>> implementations SHOULD have a max group size of 8k.
>>
>> Yes I expect. I have a ssh client from 2002 era that has worked very
> well for me (from ssh.com before they renamed it tectia) - and I would
> buy it again today - but they only to B2B these days.
>
Wait, so the ssh.com client of that era *did* do
diffie-hellman-group-exchange-sha1 (as opposed
to diffie-hellman-group1-sha1 or diffie-hellman-group14-sha1) but *didn't*
support 8k groups?
--
Darren Tucker (dtucker at zip.com.au)
GPG key 8FF4FA69 / D9A3 86E9 7EEE AF4B B2D4 37C9 C982 80C7 8FF4 FA69
Good judgement comes with experience. Unfortunately, the experience
usually comes from bad judgement.
More information about the openssh-unix-dev
mailing list