(PerSource)Penalties default perhaps too aggressive?

hvjunk hvjunk at gmail.com
Fri Sep 12 20:08:36 AEST 2025


> 
> I understand that the purpose of this script is to use the (one) working keypair(s) to "put the other ones on the server". How does it handle *that* objective in cases where it cannot observe the storage the pubkey is / may be in? And what behavior do you *want* in such a case?

What you are trying to do here (unless you are planning to code that, and I’ll be happy to beta test :)=) ) ioverengineering something, that (up till Dec’24 I believe) worked like a charm, but with the introduced (and I still believe it is over) aggressive rate limits, it fails unexpectedly for users.

As I’ve said elsewhere, I do understand the reason/case that is tried to protect, but I don’t yet see that as a valid concern in my logs up till now, and to make things less problematic, I’d rather advise on a less aggressive settings but still keep the feature in place. That way we’ll have less false positives.




More information about the openssh-unix-dev mailing list