Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.user > #186682 > unrolled thread
| Started by | Glenn English <ghe2001@gmail.com> |
|---|---|
| First post | 2017-09-11 21:10 +0200 |
| Last post | 2017-09-14 00:30 +0200 |
| Articles | 13 — 8 participants |
Back to article view | Back to linux.debian.user
Buster SSH Glenn English <ghe2001@gmail.com> - 2017-09-11 21:10 +0200
Re: Buster SSH Cindy-Sue Causey <butterflybytes@gmail.com> - 2017-09-11 23:50 +0200
Re: Buster SSH Glenn English <ghe2001@gmail.com> - 2017-09-12 00:40 +0200
Re: Buster SSH "Alexander V. Makartsev" <avbetev@gmail.com> - 2017-09-12 01:20 +0200
Re: Buster SSH Glenn English <ghe2001@gmail.com> - 2017-09-12 01:50 +0200
Re: Buster SSH Glenn English <ghe2001@gmail.com> - 2017-09-12 19:50 +0200
Re: Buster SSH Greg Wooledge <wooledg@eeg.ccf.org> - 2017-09-12 20:10 +0200
Re: Buster SSH Glenn English <ghe2001@gmail.com> - 2017-09-12 22:00 +0200
Re: Buster SSH Don Armstrong <don@debian.org> - 2017-09-13 17:40 +0200
Re: Buster SSH Nicholas Geovanis <nickgeovanis@gmail.com> - 2017-09-13 19:30 +0200
Re: Buster SSH Michael Stone <mstone@debian.org> - 2017-09-13 20:20 +0200
Re: Buster SSH Glenn English <ghe2001@gmail.com> - 2017-09-13 19:40 +0200
Re: Buster SSH Sven Hartge <sven@svenhartge.de> - 2017-09-14 00:30 +0200
| From | Glenn English <ghe2001@gmail.com> |
|---|---|
| Date | 2017-09-11 21:10 +0200 |
| Subject | Buster SSH |
| Message-ID | <uoCfM-7sQ-7@gated-at.bofh.it> |
Is there something peculiar with SSH on Buster? The key login doesn't seem to work very well -- root going out works to hosts (Wheezy, Jessie, and the one before Wheezy), but the user (me) doesn't. And nothing works coming in. Everything is fine on the non-Buster hosts. I bought a laptop recently, pulled out the Winders, and installed Buster (testing and non-free have software to make the thing work). Since the dark ages, I've been able to get around to several places with the same .ssh directory and the same login key. I've had to enable login by password to access hosts that've worked before. I've got ssh-client and ssh-server installed. -- Glenn English
[toc] | [next] | [standalone]
| From | Cindy-Sue Causey <butterflybytes@gmail.com> |
|---|---|
| Date | 2017-09-11 23:50 +0200 |
| Message-ID | <uoEKC-rj-17@gated-at.bofh.it> |
| In reply to | #186682 |
On 9/11/17, Glenn English <ghe2001@gmail.com> wrote: > Is there something peculiar with SSH on Buster? > > The key login doesn't seem to work very well -- root going out works > to hosts (Wheezy, Jessie, and the one before Wheezy), but the user > (me) doesn't. And nothing works coming in. Everything is fine on the > non-Buster hosts. > > I bought a laptop recently, pulled out the Winders, and installed > Buster (testing and non-free have software to make the thing work). > > Since the dark ages, I've been able to get around to several places > with the same .ssh directory and the same login key. > > I've had to enable login by password to access hosts that've worked > before. I've got ssh-client and ssh-server installed. I'm just feeding off your words such as key login. I don't know if it's related or not, but I've been having that occasional extra step that shows up before you can access your browser. I can't remember the exact message, but last time it was something to the effect that something didn't toggle on (login key didn't get unlocked?), likely at bootup, and that it had something to do with keyring(s). "Coincidentally" and/or maybe not was that debian-archive-keyring just updated so maybe something else related also upgraded at the same time. Be it related or not, I haven't seen that message since but have only rebooted maybe once or twice. It could end up happening again on the next reboot. Time will tell.... :) Cindy :) -- Cindy-Sue Causey Talking Rock, Pickens County, Georgia, USA * runs with duct tape *
[toc] | [prev] | [next] | [standalone]
| From | Glenn English <ghe2001@gmail.com> |
|---|---|
| Date | 2017-09-12 00:40 +0200 |
| Message-ID | <uoFwZ-16Z-5@gated-at.bofh.it> |
| In reply to | #186690 |
On Mon, Sep 11, 2017 at 9:49 PM, Cindy-Sue Causey <butterflybytes@gmail.com> wrote: > I'm just feeding off your words such as key login. I don't know if > it's related or not, but I've been having that occasional extra step > that shows up before you can access your browser. I can't remember the > exact message, but last time it was something to the effect that > something didn't toggle on (login key didn't get unlocked?), likely at > bootup, and that it had something to do with keyring(s). > > "Coincidentally" and/or maybe not was that debian-archive-keyring just > updated so maybe something else related also upgraded at the same > time. Be it related or not, I haven't seen that message since but have > only rebooted maybe once or twice. It could end up happening again on > the next reboot. > > Time will tell.... :) It will indeed. I'll check to be sure my keyrings are all up to date, but I can't understand how a Debian keyring could have anything to do with SSH. Unless a maintainer got a bright idea... Thanks. -- Glenn English
[toc] | [prev] | [next] | [standalone]
| From | "Alexander V. Makartsev" <avbetev@gmail.com> |
|---|---|
| Date | 2017-09-12 01:20 +0200 |
| Message-ID | <uoG9I-1yX-13@gated-at.bofh.it> |
| In reply to | #186691 |
There were changes in SSH in stretch. And since you told about your super old ".ssh" folder you keep tagging along, it could be the reason it causes problems for you. Here, take a look at release notes: https://www.debian.org/releases/stable/amd64/release-notes/ch-information.en.html#openssh-protocol-and-cipher-support-changes On 12.09.2017 03:30, Glenn English wrote: > On Mon, Sep 11, 2017 at 9:49 PM, Cindy-Sue Causey > <butterflybytes@gmail.com> wrote: > >> I'm just feeding off your words such as key login. I don't know if >> it's related or not, but I've been having that occasional extra step >> that shows up before you can access your browser. I can't remember the >> exact message, but last time it was something to the effect that >> something didn't toggle on (login key didn't get unlocked?), likely at >> bootup, and that it had something to do with keyring(s). >> >> "Coincidentally" and/or maybe not was that debian-archive-keyring just >> updated so maybe something else related also upgraded at the same >> time. Be it related or not, I haven't seen that message since but have >> only rebooted maybe once or twice. It could end up happening again on >> the next reboot. >> >> Time will tell.... :) > It will indeed. I'll check to be sure my keyrings are all up to date, > but I can't understand how a Debian keyring could have anything to do > with SSH. > > Unless a maintainer got a bright idea... > > Thanks. > > -- > Glenn English >
[toc] | [prev] | [next] | [standalone]
| From | Glenn English <ghe2001@gmail.com> |
|---|---|
| Date | 2017-09-12 01:50 +0200 |
| Message-ID | <uoGCL-1Nt-11@gated-at.bofh.it> |
| In reply to | #186693 |
On Mon, Sep 11, 2017 at 11:17 PM, Alexander V. Makartsev <avbetev@gmail.com> wrote: > There were changes in SSH in stretch. And since you told about your > super old ".ssh" folder you keep tagging along, it could be the reason > it causes problems for you. > Here, take a look at release notes: > https://www.debian.org/releases/stable/amd64/release-notes/ch-information.en.html#openssh-protocol-and-cipher-support-changes Wow! There sure were. Some of them don't apply, but some of them might. I'll look into them. The permissions issues look especially promising (root works, others don't). Thanks. -- Glenn English
[toc] | [prev] | [next] | [standalone]
| From | Glenn English <ghe2001@gmail.com> |
|---|---|
| Date | 2017-09-12 19:50 +0200 |
| Message-ID | <uoXtU-4mv-1@gated-at.bofh.it> |
| In reply to | #186693 |
On Mon, Sep 11, 2017 at 11:17 PM, Alexander V. Makartsev <avbetev@gmail.com> wrote: > Here, take a look at release notes: > https://www.debian.org/releases/stable/amd64/release-notes/ch-information.en.html#openssh-protocol-and-cipher-support-changes Bingo! User has dsa keys. Root has dsa and rsa keys. Thanks. Now all I have to do is figure out what I did so many years ago to generate the dsas :-) -- Glenn English
[toc] | [prev] | [next] | [standalone]
| From | Greg Wooledge <wooledg@eeg.ccf.org> |
|---|---|
| Date | 2017-09-12 20:10 +0200 |
| Message-ID | <uoXNf-4I9-19@gated-at.bofh.it> |
| In reply to | #186716 |
On Tue, Sep 12, 2017 at 05:45:13PM +0000, Glenn English wrote: > Bingo! User has dsa keys. Root has dsa and rsa keys. > > Thanks. Now all I have to do is figure out what I did so many years > ago to generate the dsas :-) You probably did ssh-keygen -t dsa. There was a period of time, about 20 years ago, when DSA keys were being promoted due to the RSA patent, which expired in 2000 in the US. More recently, it has been learned that the DSA keys are "weak" (citation needed), and so the recommendations have shifted.
[toc] | [prev] | [next] | [standalone]
| From | Glenn English <ghe2001@gmail.com> |
|---|---|
| Date | 2017-09-12 22:00 +0200 |
| Message-ID | <uoZvJ-5zK-53@gated-at.bofh.it> |
| In reply to | #186717 |
On Tue, Sep 12, 2017 at 5:59 PM, Greg Wooledge <wooledg@eeg.ccf.org> wrote: > You probably did ssh-keygen -t dsa. Probably. :-) Today, I read lots of dox and asked for an rsa -- all better now. -- Glenn English
[toc] | [prev] | [next] | [standalone]
| From | Don Armstrong <don@debian.org> |
|---|---|
| Date | 2017-09-13 17:40 +0200 |
| Message-ID | <uphVE-H9-21@gated-at.bofh.it> |
| In reply to | #186717 |
On Tue, 12 Sep 2017, Greg Wooledge wrote:
> More recently, it has been learned that the DSA keys are "weak"
> (citation needed), and so the recommendations have shifted.
https://security.stackexchange.com/questions/112802/why-openssh-deprecated-dsa-keys
and https://weakdh.org/ explain some of the rationale.
--
Don Armstrong https://www.donarmstrong.com
I always thought
violence didn't solve anything
until one day it did.
-- a softer world #470
http://www.asofterworld.com/index.php?id=470
[toc] | [prev] | [next] | [standalone]
| From | Nicholas Geovanis <nickgeovanis@gmail.com> |
|---|---|
| Date | 2017-09-13 19:30 +0200 |
| Message-ID | <upjE7-1RR-37@gated-at.bofh.it> |
| In reply to | #186747 |
[Multipart message — attachments visible in raw view] — view raw
On Wed, Sep 13, 2017 at 10:32 AM, Don Armstrong <don@debian.org> wrote: > On Tue, 12 Sep 2017, Greg Wooledge wrote: > > More recently, it has been learned that the DSA keys are "weak" > > (citation needed), and so the recommendations have shifted. > > https://security.stackexchange.com/questions/ > 112802/why-openssh-deprecated-dsa-keys > and https://weakdh.org/ explain some of the rationale. Just thinking out loud for those who won't read that article: One of its main points is not that DSA is cryptographically weak, as has been broadly mentioned. Rather that a coding flaw in ssh-keygen limits the key-size for DSA to 1024 because the developers did not track the evolving FIPS standards. Quoting: "This can be viewed as a case of OpenSSH developers being proactive in their notion of security and are ready to force users to use strong crypto. Another way of seeing the very same sequence of decisions is that OpenSSH developers blundered badly at some point because of some poor reading of FIPS 186, and then sought to cover it in the equivalent of dumping at sea the corpse of the inconvenient husband."
[toc] | [prev] | [next] | [standalone]
| From | Michael Stone <mstone@debian.org> |
|---|---|
| Date | 2017-09-13 20:20 +0200 |
| Message-ID | <upkqt-2qd-1@gated-at.bofh.it> |
| In reply to | #186749 |
On Wed, Sep 13, 2017 at 12:27:53PM -0500, Nicholas Geovanis wrote: >Just thinking out loud for those who won't read that article: >One of its main points is not that DSA is cryptographically weak, as has been >broadly mentioned. Rather that a coding flaw in ssh-keygen limits the key-size >for DSA to 1024 because the developers did not track the evolving FIPS >standards. And DSA is extremely sensitive to good random numbers, which are fairly hard to guarantee. And 1024 bit DSA is definitely too small, but larger DSA keys won't work on existing SSH implementations--from a practical standpoint, there aren't openssh servers which will take a larger, secure DSA key but won't take some other kind of key. Since there isn't a compelling reason to use DSA instead of an already-supported algorithm+keylength, why bother rolling out a change to the DSA keys? In general the security community has found that it's better to have a smaller number of well chosen options than a lot of options with little to distinguish them--when faced with too many choices, people tend to pick the wrong one. And as a bonus, elliptic curve keys are a lot smaller and a lot easier to copy & paste than humongous DSA keys. Mike Stone
[toc] | [prev] | [next] | [standalone]
| From | Glenn English <ghe2001@gmail.com> |
|---|---|
| Date | 2017-09-13 19:40 +0200 |
| Message-ID | <upjNM-1Va-21@gated-at.bofh.it> |
| In reply to | #186747 |
On Wed, Sep 13, 2017 at 3:32 PM, Don Armstrong <don@debian.org> wrote: > https://security.stackexchange.com/questions/112802/why-openssh-deprecated-dsa-keys > and https://weakdh.org/ explain some of the rationale. Very interesting indeed. And the link to Logjam (https://weakdh.org/logjam.html) is also very helpful. -- Glenn English
[toc] | [prev] | [next] | [standalone]
| From | Sven Hartge <sven@svenhartge.de> |
|---|---|
| Date | 2017-09-14 00:30 +0200 |
| Message-ID | <upokp-4Sm-11@gated-at.bofh.it> |
| In reply to | #186717 |
Greg Wooledge <wooledg@eeg.ccf.org> wrote: > On Tue, Sep 12, 2017 at 05:45:13PM +0000, Glenn English wrote: >> Bingo! User has dsa keys. Root has dsa and rsa keys. >> >> Thanks. Now all I have to do is figure out what I did so many years >> ago to generate the dsas :-) > You probably did ssh-keygen -t dsa. > There was a period of time, about 20 years ago, when DSA keys were > being promoted due to the RSA patent, which expired in 2000 in the US. > More recently, it has been learned that the DSA keys are "weak" > (citation needed), and so the recommendations have shifted. The core problem (as I understand it) of most DSA implementations is it depends on a perfect (P)RNG during operation. If your RNG is weak, an attacker could compute your private key just from observing your traffic (which the NSA for example does, as it has been proven). RSA on the other hand "only" needs a strong RNG during key creation but not during operation. Grüße, Sven. -- Sigmentation fault. Core dumped.
[toc] | [prev] | [standalone]
Back to top | Article view | linux.debian.user
csiph-web