Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.security > #6414

SHH Cipher recommendations and "prohibitions" from Debian?

From c.buhtz@posteo.jp
Newsgroups linux.debian.security
Subject SHH Cipher recommendations and "prohibitions" from Debian?
Date 2025-05-13 11:40 +0200
Message-ID <KLUhb-2Nl7-11@gated-at.bofh.it> (permalink)
Organization linux.* mail to news gateway

Show all headers | View raw


Hello,
I am upstream maintainer of "Back In Time" [1][2]. It is GUI backup 
software using rsync, where rsync is able to connect via SSH to a remote 
host.
Users are able to configure the Cipher used for that SSH connection.

The project is old and I wasn't the developer implementing this feature. 
I know nearly nothing about Ciphers and stuff like this.

I would like to give my users some hands-on about the available and used 
ciphers. I would like to warn if they use an out-dated one and I want to 
recommend some.

But to do this I need a strong, official and trustful reference. Does 
Debian has something like his?

I was able to find a list of recommendations from the BSI (a German 
institution) but without a list of out-dated Ciphers.
Also the NIST has a document, but I am not able to understand it. I 
couldn't find a list in it.

What do you think?

Regards,
Christian Buhtz

[1] -- <https://github.com/bit-team/backintime>
[2] -- <https://tracker.debian.org/pkg/backintime>

Back to linux.debian.security | Previous | NextNext in thread | Find similar


Thread

SHH Cipher recommendations and "prohibitions" from  Debian? c.buhtz@posteo.jp - 2025-05-13 11:40 +0200
  Re: SHH Cipher recommendations and "prohibitions" from Debian? Bartosz Fenski <bartosz@fenski.pl> - 2025-05-13 12:50 +0200
  Re: SHH Cipher recommendations and "prohibitions" from  Debian? c.buhtz@posteo.jp - 2025-05-13 13:20 +0200
  Use ~/.ssh/config Stephan Verbücheln <verbuecheln@posteo.de> - 2025-05-13 14:20 +0200

csiph-web