Re: best practices: public key authentication



-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Nico Kadel-Garcia wrote:
| Chuck wrote:
|> -----BEGIN PGP SIGNED MESSAGE-----
|> Hash: SHA1
|>
|> I'm curious to find out what others think about pubkey authentication
|> best practices. Assuming your private key is protected with a strong
|> passphrase, is there any value in occasionally regenerating your keypair
|> and replacing your public key on servers that you use pubkey
|> authentication with?
|
| Yes. It helps prevent fascinating man-in-the-middle attacks if you use a
| public key for multiple remote targets, and it reminds you and others to
| discard access you don't need any longer.

What exactly is a "fascinating" man in the middle attack and how does
changing my keypair prevent it? I thought MITM attacks would be detected
by the server's key changing. OpenSSH (and presumably others) warn you
if the key of the server does not match what you've previously known it
to be.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.5 (GNU/Linux)
Comment: Using GnuPG with PCLinuxOS - http://enigmail.mozdev.org

iEYEARECAAYFAkgONQ0ACgkQzIf+rZpn0oTdCwCgo6LIxrCnkgQcdmjCe7wxmfbJ
5rwAnjmYeBLztCbvvYxnMEq7RraF2wbS
=5O1W
-----END PGP SIGNATURE-----
.



Relevant Pages

  • Re: best practices: public key authentication
    ... |> Hash: SHA1 ... |> I'm curious to find out what others think about pubkey authentication ... I thought MITM attacks would be detected ...
    (comp.security.ssh)
  • Re: who do I report this to?
    ... Hash: SHA1 ... the only way to do a local test I can think of is write a network ... but it has to be under your observation and control. ...
    (freebsd-current)
  • Re: help keyboard logger!
    ... Hash: SHA1 ... In message, fegge writes ... >Peter wrote: ...
    (alt.2600)
  • Re: Windows MP 11, IE 7 and Vista...
    ... Hash: SHA1 ... I'm on the verge of installing WMP 11, ... "Usenet Filters - Learn to shut yourself the fuck up!" ...
    (alt.2600)
  • Re: unique numbers for table
    ... Hash: SHA1 ... Select Case strCounty ... Just substitute your county names in the Case lines and the appropriate ...
    (comp.databases.ms-access)