Wrong version for ext-info-s in https://www.openssh.com/specs.html

Colin Watson cjwatson at debian.org
Mon Oct 7 05:06:18 AEDT 2024


Hi,

https://www.openssh.com/specs.html says that RFC8308 support was added
in OpenSSH 7.2, and it specifically calls out both ext-info-s and
ext-info-c: "Extension Negotiation in the Secure Shell (SSH) Protocol
(ext-info-s, ext-info-c)".

However, while ext-info-c was indeed added in 7.2 as part of
server-sig-algs support
(https://anongit.mindrot.org/openssh.git/commit/?id=76c9fbbe35aabc1db977fb78e827644345e9442e),
ext-info-s was only added in 9.6 as part of implementing the
ext-info-in-auth at openssh.com extension
(https://anongit.mindrot.org/openssh.git/commit/?id=a7ed931caeb68947d30af8a795f4108b6efad761).

Could this web page be corrected in some way?

(This rabbit-hole brought to you by https://bugs.debian.org/1082730 and
https://github.com/jtesta/ssh-audit/issues/291.)

Thanks,

-- 
Colin Watson (he/him)                              [cjwatson at debian.org]


More information about the openssh-unix-dev mailing list