[Bug 2302] with DH-GEX, ssh (and sshd) should not fall back to unconfigured DH groups or at least document this behaviour and use a stronger group

Darren Tucker dtucker at zip.com.au
Fri Jul 10 20:06:52 AEST 2015


On Fri, Jul 10, 2015 at 8:01 PM, aixtools <aixtools at gmail.com> wrote:

> On 2015-06-02 5:31 AM, bugzilla-daemon at mindrot.org wrote:

[...]

> Do any such clients actually exist?  RFC4419 says DH-GEX
>> implementations SHOULD have a max group size of 8k.
>>
>>  Yes I expect. I have a ssh client from 2002 era that has worked very
> well for me (from ssh.com before they renamed it tectia) - and I would
> buy it again today - but they only to B2B these days.
>

Wait, so the ssh.com client of that era *did* do
diffie-hellman-group-exchange-sha1 (as opposed
to  diffie-hellman-group1-sha1 or diffie-hellman-group14-sha1) but *didn't*
support 8k groups?

-- 
Darren Tucker (dtucker at zip.com.au)
GPG key 8FF4FA69 / D9A3 86E9 7EEE AF4B B2D4  37C9 C982 80C7 8FF4 FA69
    Good judgement comes with experience. Unfortunately, the experience
usually comes from bad judgement.


More information about the openssh-unix-dev mailing list