Re: passphrase/ssh2

From: Michael Mannsberger (mm450exc_at_gmail.com)
Date: 08/04/05

  • Next message: Jeff Rosowski: "Re: Effective bandwidth reduction over WAN"
    Date: Thu, 4 Aug 2005 09:44:52 -0400
    To: Ken Garland <ken.garland@rotech.com>
    
    

    The last two characters of the key are a NULL character and a 0 or 1
    at the end. If the last character is set to 0 you the key has to
    passphrase. If set to 1 it does. Just write a little C program which
    reads the files(fgetc).

    On 8/4/05, Ken Garland <ken.garland@rotech.com> wrote:
    > Michael Mannsberger wrote:
    >
    > >How can I check if a ssh2 key has a passphrase set or not? I know the
    > >structure of a ssh1 private key but can't find anything on ssh2.
    > >
    > >-mike
    > >
    > >
    > How do you check ssh1 for passphrase?
    >
    >
    >


  • Next message: Jeff Rosowski: "Re: Effective bandwidth reduction over WAN"

    Relevant Pages

    • RE: ADS Password Storage Protection
      ... Regarding the shorter complex passwords, my understanding is that the reason many organizations recommend a complex password but only up to 8 characters long is because many unix systems don't support a password longer than that. ... For purposes of a password policy for windows users - if I understand your comments - we would suggest a 15-character minimum password, and it can be a passphrase, but we should try to make it something that wouldn't appear in some body of work that would be a candidate for digitizing for purposes of a password attack. ... A passphrase that is a real phrase would make it easier for users to remember their password, but if it could be made much stronger by changing only one character it would be less of a burden on the users to remember. ...
      (Security-Basics)
    • RE: ADS Password Storage Protection
      ... About your comment that some researchers have concluded that a typical passphrase containing only whole words is less secure than a much shorter, more complex password - I assume you're not suggesting using a short complex password but to instead somehow alter the longer passphrase, to make the passphrase more difficult to crack but still easy to remember? ... treat each word as character, and apply varying combinations of those ... its hybrid attack. ...
      (Security-Basics)
    • Re: Help secure my data (They will steal my drive)
      ... but it supports strong password-based encryption and can be ... printable ascii characters about 6.5 bit per character. ... In case your passphrase is not trivial it's much more likely an attacker ... will try to recover plaintext from swap files/virtual memory and from ...
      (sci.crypt)
    • RE: Controlling ssh from an external program
      ... passphrase could be discovered and the private key would fall into dangerous ... NB the SSH environment strings need to be included in this mixture! ... character as the final character could signify accept from a file. ... Controlling ssh from an external program ...
      (SSH)
    • Re: The Chinese MD5 attack
      ... >> Assuming a common passphrase length of around 20 characters, ... >> This will yield the entire original passphrase, ... The circumstance being 20 character English password? ... with far more than 16 bytes worth of entropy. ...
      (sci.crypt)

  • Quantcast