Alternative check for depeciated ssh-rsa signature?

M Rubon rubonmtz at gmail.com
Wed Sep 1 00:46:59 AEST 2021


The recent release notes suggesting testing with
   ssh -oHostKeyAlgorithms=-ssh-rsa user at host

I want to test with dropbear clients where I do not have fine grained
control of algorithms.  I think, but want to confirm, that an
equivalent server side test is to run sshd with the sshd_config line
   HostKeyAlgorithms   -ssh-rsa,ssh-rsa-cert-v01 at openssh.com

Thanks!

M


More information about the openssh-unix-dev mailing list