Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.user > #186749
| From | Nicholas Geovanis <nickgeovanis@gmail.com> |
|---|---|
| Newsgroups | linux.debian.user |
| Subject | Re: Buster SSH |
| Date | 2017-09-13 19:30 +0200 |
| Message-ID | <upjE7-1RR-37@gated-at.bofh.it> (permalink) |
| References | (2 earlier) <uoFwZ-16Z-5@gated-at.bofh.it> <uoG9I-1yX-13@gated-at.bofh.it> <uoXtU-4mv-1@gated-at.bofh.it> <uoXNf-4I9-19@gated-at.bofh.it> <uphVE-H9-21@gated-at.bofh.it> |
| Organization | linux.* mail to news gateway |
[Multipart message — attachments visible in raw view] - view raw
On Wed, Sep 13, 2017 at 10:32 AM, Don Armstrong <don@debian.org> wrote: > On Tue, 12 Sep 2017, Greg Wooledge wrote: > > More recently, it has been learned that the DSA keys are "weak" > > (citation needed), and so the recommendations have shifted. > > https://security.stackexchange.com/questions/ > 112802/why-openssh-deprecated-dsa-keys > and https://weakdh.org/ explain some of the rationale. Just thinking out loud for those who won't read that article: One of its main points is not that DSA is cryptographically weak, as has been broadly mentioned. Rather that a coding flaw in ssh-keygen limits the key-size for DSA to 1024 because the developers did not track the evolving FIPS standards. Quoting: "This can be viewed as a case of OpenSSH developers being proactive in their notion of security and are ready to force users to use strong crypto. Another way of seeing the very same sequence of decisions is that OpenSSH developers blundered badly at some point because of some poor reading of FIPS 186, and then sought to cover it in the equivalent of dumping at sea the corpse of the inconvenient husband."
Back to linux.debian.user | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread
Buster SSH Glenn English <ghe2001@gmail.com> - 2017-09-11 21:10 +0200
Re: Buster SSH Cindy-Sue Causey <butterflybytes@gmail.com> - 2017-09-11 23:50 +0200
Re: Buster SSH Glenn English <ghe2001@gmail.com> - 2017-09-12 00:40 +0200
Re: Buster SSH "Alexander V. Makartsev" <avbetev@gmail.com> - 2017-09-12 01:20 +0200
Re: Buster SSH Glenn English <ghe2001@gmail.com> - 2017-09-12 01:50 +0200
Re: Buster SSH Glenn English <ghe2001@gmail.com> - 2017-09-12 19:50 +0200
Re: Buster SSH Greg Wooledge <wooledg@eeg.ccf.org> - 2017-09-12 20:10 +0200
Re: Buster SSH Glenn English <ghe2001@gmail.com> - 2017-09-12 22:00 +0200
Re: Buster SSH Don Armstrong <don@debian.org> - 2017-09-13 17:40 +0200
Re: Buster SSH Nicholas Geovanis <nickgeovanis@gmail.com> - 2017-09-13 19:30 +0200
Re: Buster SSH Michael Stone <mstone@debian.org> - 2017-09-13 20:20 +0200
Re: Buster SSH Glenn English <ghe2001@gmail.com> - 2017-09-13 19:40 +0200
Re: Buster SSH Sven Hartge <sven@svenhartge.de> - 2017-09-14 00:30 +0200
csiph-web