Re: Export restrictions / SSH session key




"quebert" <isquereal@xxxxxxxx> wrote in message
news:1148306061.546126.106010@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
Hello,

i have a question regarding the export restrictions (in Europe) when
using SSH. We would like to implement / use SSH in one of our
products. The only cipher which we would like to support is DES,
nothing else.

DES is demonstrably no longer secure, as described at
http://www.interesting-people.org/archives/interesting-people/199807/msg00049.html.

Which crypto regulations are you worrying about, and what do they say?

I generate the host key using
--> ssh-keygen -q -t rsa1 -f host.key -C '' -N '' <--
and copy it to the server (a small embedded box).
This is also possible for the customer.

My questions now:
Does the host key also fall under the export restrictions, if we
install
it fix on the device?
Does the by RSA (in SSHv1) generated session key (used for the cipher,
DES in our case),
fall under the export restrictions?

Kind Regards,
Quebert

You really, really need to talk to a local, technically competent lawyer or
whoever writes your country's regulations. They do vary from country to
country.


.



Relevant Pages

  • Export restrictions / SSH session key
    ... We would like to implement / use SSH in one of our ... The only cipher which we would like to support is DES, ... Does the host key also fall under the export restrictions, ...
    (comp.security.ssh)
  • Re: Export restrictions / SSH session key
    ... quebert> when using SSH. ... quebert> like to support is DES, ... Does the host key also fall under the ...
    (comp.security.ssh)
  • [NEWS] SSH Protocol Weakness Vulnerability (MITM)
    ... A weakness in the backward compatibility of the SSH Protocol has been ... SSH version 1.0) is unlikely to have the host key for the other protocol ... The SSH daemons advertise one of two major versions, ...
    (Securiteam)
  • Re: Q: paramiko/SSH/ how to get a remote host_key
    ... SSH client, if you connect for the first time then you get somethign ... ''' The server's host key is not cached in the registry. ... host_key the first time it connects to a remote SSH server. ...
    (comp.lang.python)
  • Re: two attempted break-ins from Hong Kong & Italy
    ... > country: IT ... > source: RIPE # Filtered ... > The second from Hong Kong had the IP 210.17.180.83, ... > who wanted to log in via ssh as root. ...
    (comp.security.misc)