Re: null cipher

From: David Magda (dmagda+usenet@ee.ryerson.ca)
Date: 07/23/02


From: David Magda <dmagda+usenet@ee.ryerson.ca>
Date: 23 Jul 2002 16:43:25 -0400

those who know me have no need of my name <not-a-real-address@usa.net> writes:

> from the number of posts here it would benefit a certain segment of the ssh
> using community. (they would be better served using ldap or kerberos, but
> some people think that ssh should solve all problems.)

I just want to specify that the NULL cipher is a valid option. The
OpenSSH developers have made set things up that it is rejected even
if the administrator asks for it. I understand their reasons, but I
don't like that I can't enforce policy the way I see fit.

I *want* to be able to shoot myself in the foot if I ask for it -
that is the *nix way. :> I understand the risks and am willing to
accept them.

> blowfish is fairly quick. have you tried it?

We use it by default. That and straight DES. It (DES) is secure
enough for our internal needs and fairly quick. Anything from outside
we force Blowfish, Twofish, AES or 3DES for obvious reasons.

> never said it would be easy. ldap or kerberos would be much better than
> trying to wedge ssh into a role it was never designed to fill.

We like SSH and it works well. Just want minimal encryption where
it's not needed.

> then maybe it's time to reconsider the distribution you use.

We have considered all the other distributions. Slackware is the
"best" one for us. All the others use unmanageable packaging systems
to make things more "manageable". Even Debian's wonderful .deb is too
intrusive. <sigh>

-- 
David Magda <dmagda at ee.ryerson.ca>
Because the innovator has for enemies all those who have done well under
the old conditions, and lukewarm defenders in those who may do well 
under the new. -- Niccolo Machiavelli, _The Prince_, Chapter VI



Relevant Pages

  • Trouble with nss|pam|openldap
    ... It appears as though the system is using ldap, but I can't seem to ssh in as an LDAP user. ... # id testuser seems to work, ... objectClass: person ...
    (freebsd-questions)
  • Re: ssh+ldap+freebsd5.2 problem
    ... I can not SSH using my LDAP account ... Have any body manage to configure ssh with openldap on ... Download Messenger Now ...
    (freebsd-questions)
  • Re: Machine not locked-up but cant log on either
    ... I'm also limiting who is allow to connect through ssh via ... I'm restricting it to the ISPs of our users. ... Probably DNS lookup is timing out and then either the LDAP bind process ... In the end, the local authentication never ...
    (RedHat)
  • Re: ssh, sudo and ldap
    ... SSH and sudo both defer to PAM; if your client is set up to auth ... with LDAP as well. ... PAM, e.g., Samba. ...
    (RedHat)
  • Re: SSH and LDAP (how to get it to work)
    ... > Can someone please explain how to implement SSH and LDAP together. ... LDAP server: ... A useful tool to debug your server is snoop ...
    (comp.unix.solaris)

Quantcast