Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #186682 > unrolled thread

Buster SSH

Started byGlenn English <ghe2001@gmail.com>
First post2017-09-11 21:10 +0200
Last post2017-09-14 00:30 +0200
Articles 13 — 8 participants

Back to article view | Back to linux.debian.user


Contents

  Buster SSH Glenn English <ghe2001@gmail.com> - 2017-09-11 21:10 +0200
    Re: Buster SSH Cindy-Sue Causey <butterflybytes@gmail.com> - 2017-09-11 23:50 +0200
      Re: Buster SSH Glenn English <ghe2001@gmail.com> - 2017-09-12 00:40 +0200
        Re: Buster SSH "Alexander V. Makartsev" <avbetev@gmail.com> - 2017-09-12 01:20 +0200
          Re: Buster SSH Glenn English <ghe2001@gmail.com> - 2017-09-12 01:50 +0200
          Re: Buster SSH Glenn English <ghe2001@gmail.com> - 2017-09-12 19:50 +0200
            Re: Buster SSH Greg Wooledge <wooledg@eeg.ccf.org> - 2017-09-12 20:10 +0200
              Re: Buster SSH Glenn English <ghe2001@gmail.com> - 2017-09-12 22:00 +0200
              Re: Buster SSH Don Armstrong <don@debian.org> - 2017-09-13 17:40 +0200
                Re: Buster SSH Nicholas Geovanis <nickgeovanis@gmail.com> - 2017-09-13 19:30 +0200
                  Re: Buster SSH Michael Stone <mstone@debian.org> - 2017-09-13 20:20 +0200
                Re: Buster SSH Glenn English <ghe2001@gmail.com> - 2017-09-13 19:40 +0200
              Re: Buster SSH Sven Hartge <sven@svenhartge.de> - 2017-09-14 00:30 +0200

#186682 — Buster SSH

FromGlenn English <ghe2001@gmail.com>
Date2017-09-11 21:10 +0200
SubjectBuster SSH
Message-ID<uoCfM-7sQ-7@gated-at.bofh.it>
Is there something peculiar with SSH on Buster?

The key login doesn't seem to work very well -- root going out works
to hosts (Wheezy, Jessie, and the one before Wheezy), but the user
(me) doesn't. And nothing works coming in. Everything is fine on the
non-Buster hosts.

I bought a laptop recently, pulled out the Winders, and installed
Buster (testing and non-free have software to make the thing work).

Since the dark ages, I've been able to get around to several places
with the same .ssh directory and the same login key.

I've had to enable login by password to access hosts that've worked
before. I've got ssh-client and ssh-server installed.

--
Glenn English

[toc] | [next] | [standalone]


#186690

FromCindy-Sue Causey <butterflybytes@gmail.com>
Date2017-09-11 23:50 +0200
Message-ID<uoEKC-rj-17@gated-at.bofh.it>
In reply to#186682
On 9/11/17, Glenn English <ghe2001@gmail.com> wrote:
> Is there something peculiar with SSH on Buster?
>
> The key login doesn't seem to work very well -- root going out works
> to hosts (Wheezy, Jessie, and the one before Wheezy), but the user
> (me) doesn't. And nothing works coming in. Everything is fine on the
> non-Buster hosts.
>
> I bought a laptop recently, pulled out the Winders, and installed
> Buster (testing and non-free have software to make the thing work).
>
> Since the dark ages, I've been able to get around to several places
> with the same .ssh directory and the same login key.
>
> I've had to enable login by password to access hosts that've worked
> before. I've got ssh-client and ssh-server installed.


I'm just feeding off your words such as key login. I don't know if
it's related or not, but I've been having that occasional extra step
that shows up before you can access your browser. I can't remember the
exact message, but last time it was something to the effect that
something didn't toggle on (login key didn't get unlocked?), likely at
bootup, and that it had something to do with keyring(s).

"Coincidentally" and/or maybe not was that debian-archive-keyring just
updated so maybe something else related also upgraded at the same
time. Be it related or not, I haven't seen that message since but have
only rebooted maybe once or twice. It could end up happening again on
the next reboot. Time will tell.... :)

Cindy :)
-- 
Cindy-Sue Causey
Talking Rock, Pickens County, Georgia, USA

* runs with duct tape *

[toc] | [prev] | [next] | [standalone]


#186691

FromGlenn English <ghe2001@gmail.com>
Date2017-09-12 00:40 +0200
Message-ID<uoFwZ-16Z-5@gated-at.bofh.it>
In reply to#186690
On Mon, Sep 11, 2017 at 9:49 PM, Cindy-Sue Causey
<butterflybytes@gmail.com> wrote:

> I'm just feeding off your words such as key login. I don't know if
> it's related or not, but I've been having that occasional extra step
> that shows up before you can access your browser. I can't remember the
> exact message, but last time it was something to the effect that
> something didn't toggle on (login key didn't get unlocked?), likely at
> bootup, and that it had something to do with keyring(s).
>
> "Coincidentally" and/or maybe not was that debian-archive-keyring just
> updated so maybe something else related also upgraded at the same
> time. Be it related or not, I haven't seen that message since but have
> only rebooted maybe once or twice. It could end up happening again on
> the next reboot.
>
> Time will tell.... :)

It will indeed. I'll check to be sure my keyrings are all up to date,
but I can't understand how a Debian keyring could have anything to do
with SSH.

Unless a maintainer got a bright idea...

Thanks.

--
Glenn English

[toc] | [prev] | [next] | [standalone]


#186693

From"Alexander V. Makartsev" <avbetev@gmail.com>
Date2017-09-12 01:20 +0200
Message-ID<uoG9I-1yX-13@gated-at.bofh.it>
In reply to#186691
There were changes in SSH in stretch. And since you told about your
super old ".ssh" folder you keep tagging along, it could be the reason
it causes problems for you.
Here, take a look at release notes:
https://www.debian.org/releases/stable/amd64/release-notes/ch-information.en.html#openssh-protocol-and-cipher-support-changes


On 12.09.2017 03:30, Glenn English wrote:
> On Mon, Sep 11, 2017 at 9:49 PM, Cindy-Sue Causey
> <butterflybytes@gmail.com> wrote:
>
>> I'm just feeding off your words such as key login. I don't know if
>> it's related or not, but I've been having that occasional extra step
>> that shows up before you can access your browser. I can't remember the
>> exact message, but last time it was something to the effect that
>> something didn't toggle on (login key didn't get unlocked?), likely at
>> bootup, and that it had something to do with keyring(s).
>>
>> "Coincidentally" and/or maybe not was that debian-archive-keyring just
>> updated so maybe something else related also upgraded at the same
>> time. Be it related or not, I haven't seen that message since but have
>> only rebooted maybe once or twice. It could end up happening again on
>> the next reboot.
>>
>> Time will tell.... :)
> It will indeed. I'll check to be sure my keyrings are all up to date,
> but I can't understand how a Debian keyring could have anything to do
> with SSH.
>
> Unless a maintainer got a bright idea...
>
> Thanks.
>
> --
> Glenn English
>

[toc] | [prev] | [next] | [standalone]


#186694

FromGlenn English <ghe2001@gmail.com>
Date2017-09-12 01:50 +0200
Message-ID<uoGCL-1Nt-11@gated-at.bofh.it>
In reply to#186693
On Mon, Sep 11, 2017 at 11:17 PM, Alexander V. Makartsev
<avbetev@gmail.com> wrote:
> There were changes in SSH in stretch. And since you told about your
> super old ".ssh" folder you keep tagging along, it could be the reason
> it causes problems for you.
> Here, take a look at release notes:
> https://www.debian.org/releases/stable/amd64/release-notes/ch-information.en.html#openssh-protocol-and-cipher-support-changes

Wow! There sure were. Some of them don't apply, but some of them
might. I'll look into them. The permissions issues look especially
promising (root works, others don't).

Thanks.

--
Glenn English

[toc] | [prev] | [next] | [standalone]


#186716

FromGlenn English <ghe2001@gmail.com>
Date2017-09-12 19:50 +0200
Message-ID<uoXtU-4mv-1@gated-at.bofh.it>
In reply to#186693
On Mon, Sep 11, 2017 at 11:17 PM, Alexander V. Makartsev
<avbetev@gmail.com> wrote:

> Here, take a look at release notes:
> https://www.debian.org/releases/stable/amd64/release-notes/ch-information.en.html#openssh-protocol-and-cipher-support-changes

Bingo! User has dsa keys. Root has dsa and rsa keys.

Thanks. Now all I have to do is figure out what I did so many years
ago to generate the dsas :-)

--
Glenn English

[toc] | [prev] | [next] | [standalone]


#186717

FromGreg Wooledge <wooledg@eeg.ccf.org>
Date2017-09-12 20:10 +0200
Message-ID<uoXNf-4I9-19@gated-at.bofh.it>
In reply to#186716
On Tue, Sep 12, 2017 at 05:45:13PM +0000, Glenn English wrote:
> Bingo! User has dsa keys. Root has dsa and rsa keys.
> 
> Thanks. Now all I have to do is figure out what I did so many years
> ago to generate the dsas :-)

You probably did ssh-keygen -t dsa.

There was a period of time, about 20 years ago, when DSA keys were being
promoted due to the RSA patent, which expired in 2000 in the US.  More
recently, it has been learned that the DSA keys are "weak" (citation
needed), and so the recommendations have shifted.

[toc] | [prev] | [next] | [standalone]


#186718

FromGlenn English <ghe2001@gmail.com>
Date2017-09-12 22:00 +0200
Message-ID<uoZvJ-5zK-53@gated-at.bofh.it>
In reply to#186717
On Tue, Sep 12, 2017 at 5:59 PM, Greg Wooledge <wooledg@eeg.ccf.org> wrote:

> You probably did ssh-keygen -t dsa.

Probably. :-) Today, I read lots of dox and asked for an rsa -- all better now.

--
Glenn English

[toc] | [prev] | [next] | [standalone]


#186747

FromDon Armstrong <don@debian.org>
Date2017-09-13 17:40 +0200
Message-ID<uphVE-H9-21@gated-at.bofh.it>
In reply to#186717
On Tue, 12 Sep 2017, Greg Wooledge wrote:
> More recently, it has been learned that the DSA keys are "weak"
> (citation needed), and so the recommendations have shifted.

https://security.stackexchange.com/questions/112802/why-openssh-deprecated-dsa-keys
and https://weakdh.org/ explain some of the rationale.

-- 
Don Armstrong                      https://www.donarmstrong.com

I always thought
violence didn't solve anything
until one day it did.
 -- a softer world #470
    http://www.asofterworld.com/index.php?id=470

[toc] | [prev] | [next] | [standalone]


#186749

FromNicholas Geovanis <nickgeovanis@gmail.com>
Date2017-09-13 19:30 +0200
Message-ID<upjE7-1RR-37@gated-at.bofh.it>
In reply to#186747

[Multipart message — attachments visible in raw view] — view raw

On Wed, Sep 13, 2017 at 10:32 AM, Don Armstrong <don@debian.org> wrote:

> On Tue, 12 Sep 2017, Greg Wooledge wrote:
> > More recently, it has been learned that the DSA keys are "weak"
> > (citation needed), and so the recommendations have shifted.
>
> https://security.stackexchange.com/questions/
> 112802/why-openssh-deprecated-dsa-keys
> and https://weakdh.org/ explain some of the rationale.


Just thinking out loud for those who won't read that article:
One of its main points is not that DSA is cryptographically weak, as has
been broadly mentioned. Rather that a coding flaw in ssh-keygen limits the
key-size for DSA to 1024 because the developers did not track the evolving
FIPS standards.

Quoting: "This can be viewed as a case of OpenSSH developers being
proactive in their notion of security and are ready to force users to use
strong crypto. Another way of seeing the very same sequence of decisions is
that OpenSSH developers blundered badly at some point because of some poor
reading of FIPS 186, and then sought to cover it in the equivalent of
dumping at sea the corpse of the inconvenient husband."

[toc] | [prev] | [next] | [standalone]


#186752

FromMichael Stone <mstone@debian.org>
Date2017-09-13 20:20 +0200
Message-ID<upkqt-2qd-1@gated-at.bofh.it>
In reply to#186749
On Wed, Sep 13, 2017 at 12:27:53PM -0500, Nicholas Geovanis wrote:
>Just thinking out loud for those who won't read that article:
>One of its main points is not that DSA is cryptographically weak, as has been
>broadly mentioned. Rather that a coding flaw in ssh-keygen limits the key-size
>for DSA to 1024 because the developers did not track the evolving FIPS
>standards.

And DSA is extremely sensitive to good random numbers, which are fairly 
hard to guarantee. And 1024 bit DSA is definitely too small, but larger 
DSA keys won't work on existing SSH implementations--from a practical 
standpoint, there aren't openssh servers which will take a larger, 
secure DSA key but won't take some other kind of key. Since there isn't 
a compelling reason to use DSA instead of an already-supported 
algorithm+keylength, why bother rolling out a change to the DSA keys? In 
general the security community has found that it's better to have a 
smaller number of well chosen options than a lot of options with little 
to distinguish them--when faced with too many choices, people tend to 
pick the wrong one. And as a bonus, elliptic curve keys are a lot 
smaller and a lot easier to copy & paste than humongous DSA keys.

Mike Stone

[toc] | [prev] | [next] | [standalone]


#186750

FromGlenn English <ghe2001@gmail.com>
Date2017-09-13 19:40 +0200
Message-ID<upjNM-1Va-21@gated-at.bofh.it>
In reply to#186747
On Wed, Sep 13, 2017 at 3:32 PM, Don Armstrong <don@debian.org> wrote:

> https://security.stackexchange.com/questions/112802/why-openssh-deprecated-dsa-keys
> and https://weakdh.org/ explain some of the rationale.

Very interesting indeed. And the link to Logjam
(https://weakdh.org/logjam.html) is also very helpful.

--
Glenn English

[toc] | [prev] | [next] | [standalone]


#186765

FromSven Hartge <sven@svenhartge.de>
Date2017-09-14 00:30 +0200
Message-ID<upokp-4Sm-11@gated-at.bofh.it>
In reply to#186717
Greg Wooledge <wooledg@eeg.ccf.org> wrote:
> On Tue, Sep 12, 2017 at 05:45:13PM +0000, Glenn English wrote:

>> Bingo! User has dsa keys. Root has dsa and rsa keys.
>> 
>> Thanks. Now all I have to do is figure out what I did so many years
>> ago to generate the dsas :-)

> You probably did ssh-keygen -t dsa.

> There was a period of time, about 20 years ago, when DSA keys were
> being promoted due to the RSA patent, which expired in 2000 in the US.
> More recently, it has been learned that the DSA keys are "weak"
> (citation needed), and so the recommendations have shifted.

The core problem (as I understand it) of most DSA implementations is it
depends on a perfect (P)RNG during operation. If your RNG is weak, an
attacker could compute your private key just from observing your traffic
(which the NSA for example does, as it has been proven).

RSA on the other hand "only" needs a strong RNG during key creation but
not during operation.

Grüße,
Sven.

-- 
Sigmentation fault. Core dumped.

[toc] | [prev] | [standalone]


Back to top | Article view | linux.debian.user


csiph-web