Re: "Host key did not match signature" error during rekey



receive rekey SSH_MSG_KEXDH_INIT
extract mpint e (as per RFC 4253 section 8 for SSH_MSG_KEXDH_INIT)
save exchange hash H
generate new keys (incoming and outgoing encryption keys, mac keys)
extract mpint f (as required in RFC 4253 section 8 for
SSH_MSG_KEXDH_REPLY)
generate shared secret
generate signature of H
create SSH_MSG_KEXDH_REPLY from server hostkey, mpint f and signature
of F


The last line should read
"create SSH_MSG_KEXDH_REPLY from server hostkey, mpint f and signature
of H"

.



Relevant Pages

  • Re: native xml processing vs what Postgres and Oracle offer
    ... replies to replies are often more comprehensible when ... So I'm not sure what "message id" means here, whether you mean it in a general sense or to stand for what some rfc's call "message-id" or "msg id". ... If you are talking about keys, I would note the similarity with the RM and this from rfc 3977: "Each article MUST have a unique message-id; two articles offered by an NNTP server MUST NOT have the same message-id." ...
    (comp.databases.theory)
  • Re: public key anderer Mailadrese zuordnen
    ... Du klatschst UserID Pakete nach RfC 2440 dran. ... Im Ernst: Der Empfänger soll Dir die Keys schicken und Du bindest sie ein. ...
    (de.comp.security.misc)
  • Re: Keyboard Message Not getting Processed....
    ... where in i have an Text Box control. ... all the keys are Processed except +%,RETURN key and & ... With sufficient thrust, pigs fly just fine. ... -- RFC 1925 ...
    (microsoft.public.vc.atl)