Re: ssh host key inconsistency

From: Cedric Ware (cedric.ware@enst.fr)
Date: 07/26/02


Date: Fri, 26 Jul 2002 19:07:36 +0200
From: Cedric Ware <cedric.ware@enst.fr>
To: Dag-Erling Smorgrav <des@ofug.org>


> According to the draft standard, RSA is deprecated and DSA is the
> preferred cipher.

Do you have any references for this? I have looked through
http://www.ietf.org/html.charters/secsh-charter.html, but I must
have missed it.

> There's also a POLA issue; previous FreeBSD
> releases have used only DSA, and enabling RSA would cause spurious
> "unknown host key" warnings

Indeed. (Although I am somewhat in the reverse situation, not being
a FreeBSD-only user...)

                                                Thank you,
                                                Cedric Ware.

To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message



Relevant Pages

  • Re: ssh host key inconsistency
    ... > both the RSA and DSA keys?) ... RSA is deprecated and DSA is the ... with "unsubscribe freebsd-security" in the body of the message ...
    (FreeBSD-Security)
  • Re: RSA or DSA?
    ... The SSH 1 protocol only supports RSA keys; ... supported by PuTTY are RSA and DSA. ... The PuTTY developers strongly recommend you use RSA. ...
    (comp.security.ssh)
  • Re: ssh-keygen between SuSE and FreeBSD
    ... I'm not quite sure right now why you're using rsa keys. ... dsa keys. ... ssh version 1, while dsa keys are for ssh version 2. ...
    (freebsd-stable)
  • Re: RSA or DSA?
    ... >> to dsa. ... > The PuTTY developers strongly recommend you use RSA. ... directed at _Windows_ SSH clients, ...
    (comp.security.ssh)
  • Re: Multiple keys in .ssh/authorized_keys file?
    ... It's not necessary but may be useful depending on your configuration. ... provided you have your ssh2 private keys on the nodes you expect to ... DSA is mandatory in the spec while RSA is recommended. ...
    (comp.security.ssh)