Obsolete MD5

Fedor Brunner fedor.brunner at azet.sk
Mon May 4 23:30:45 AEST 2015


Hi,
are there any plans to obsolete the MD5 in OpenSSH ?

Would it be possible to remove
hmac-md5-etm at openssh.com,hmac-md5-96-etm at openssh.com,hmac-md5,hmac-md5-96 from
the default list of MACs ?

http://www.di.ens.fr/~fouque/pub/crypto07b.pdf

According to RFC 4253, hmac-md5 and hmac-md5-96 are only optional.

Fedor


More information about the openssh-unix-dev mailing list