[Patch] TCP MD5SIG for OpenSSH
Malcolm
opensshdev at r.paypc.com
Fri Jan 15 22:27:19 AEDT 2016
Quoting Alex Bligh <alex at alex.org.uk>:
> So could they exchange a secret as part of the session, obviating
> the need for any set up?
If by set up, you mean "the rest of the SSH authentication", then surely not.
MD5 pre-shared secrets are probably fine for "port-knocking" or even
RST-proofing purposes, but not for authenticating SSH sessions to servers.
=M=
More information about the openssh-unix-dev
mailing list