Checking private keys for empty passphrases / cracking passphrases on

From: Ed Voncken (vonckene@asa-ehv.ce.philips.com)
Date: 03/18/02


Date: Mon, 18 Mar 2002 14:48:40 +0100
From: Ed Voncken <vonckene@asa-ehv.ce.philips.com>

Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: 7bit

Hello,

We are busy implementing OpenSSH for most of our Sun Solaris 8
infrastructure. So far, the software is runnning just fine and people
are getting used to the advantages of ssh-agent with keys.

For auditing purposes, I would like to detect keys with empty
passphrases and report them to Security.

Ideally, I would like to run something like 'crack' against private keys
and see if they use a weak passphrase.

Has any of this ever been done? Google and the OpenSSH and Snailbook
FAQs did not provide any pointers.

Any help is appreciated.

-- 
Greetings,
  Ed Voncken
  Remove all SPAM to reply...

** Not speaking on behalf of current or any previous employer **



Relevant Pages

  • RE: [USN-612-2] OpenSSH vulnerability
    ... The update for Ubuntu 8.04 was as ... (part of the ssh-server install was a blacklist of keys not to use). ... particularly affects the use of encryption keys in OpenSSH. ... amd64 architecture: ...
    (Ubuntu)
  • [Full-disclosure] [USN-612-2] OpenSSH vulnerability
    ... particularly affects the use of encryption keys in OpenSSH. ... Ubuntu) are based on Debian. ... amd64 architecture: ...
    (Full-Disclosure)
  • [USN-612-2] OpenSSH vulnerability
    ... particularly affects the use of encryption keys in OpenSSH. ... Ubuntu) are based on Debian. ... amd64 architecture: ...
    (Bugtraq)
  • Re: question regarding SSH and interoperability with PKI
    ... OpenSSH read user identity and server host keys from files in PEM format. ... After this is good to create OpenSSH public key - command is: ...
    (SSH)
  • Institutional OpenSSH Key Deployment -- How?
    ... and various SSH FAQs for, and haven't come up with very much, so I -do- ... we're trying to encourage people to use public keys and passphrases ... OpenSSH is that there aren't any particularly obvious ways to distribute ... We have an institutional LDAP user directory, ...
    (comp.security.ssh)

Quantcast