Fallback mechanism for external security key libraries

Damien Miller djm at mindrot.org
Tue Sep 22 10:13:38 AEST 2020


On Mon, 21 Sep 2020, Reza Tavakoli wrote:

> Hello,
> Due to many changes in sk-api.h system, can we add a fallback mechanic to
> switch to internal implementation if the current library version does not
> match the installed OpenSSH? It can be controllable via some settings or
> parameters. I can start working on a patch if you think this is good idea.

I think it would be better to eventually have ssh-sk.c allow support for
older API versions, but only once FIDO support is a little less new and
has had time to stabilise.

-d


More information about the openssh-unix-dev mailing list