Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #186749

Re: Buster SSH

From Nicholas Geovanis <nickgeovanis@gmail.com>
Newsgroups linux.debian.user
Subject Re: Buster SSH
Date 2017-09-13 19:30 +0200
Message-ID <upjE7-1RR-37@gated-at.bofh.it> (permalink)
References (2 earlier) <uoFwZ-16Z-5@gated-at.bofh.it> <uoG9I-1yX-13@gated-at.bofh.it> <uoXtU-4mv-1@gated-at.bofh.it> <uoXNf-4I9-19@gated-at.bofh.it> <uphVE-H9-21@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


[Multipart message — attachments visible in raw view] - view raw

On Wed, Sep 13, 2017 at 10:32 AM, Don Armstrong <don@debian.org> wrote:

> On Tue, 12 Sep 2017, Greg Wooledge wrote:
> > More recently, it has been learned that the DSA keys are "weak"
> > (citation needed), and so the recommendations have shifted.
>
> https://security.stackexchange.com/questions/
> 112802/why-openssh-deprecated-dsa-keys
> and https://weakdh.org/ explain some of the rationale.


Just thinking out loud for those who won't read that article:
One of its main points is not that DSA is cryptographically weak, as has
been broadly mentioned. Rather that a coding flaw in ssh-keygen limits the
key-size for DSA to 1024 because the developers did not track the evolving
FIPS standards.

Quoting: "This can be viewed as a case of OpenSSH developers being
proactive in their notion of security and are ready to force users to use
strong crypto. Another way of seeing the very same sequence of decisions is
that OpenSSH developers blundered badly at some point because of some poor
reading of FIPS 186, and then sought to cover it in the equivalent of
dumping at sea the corpse of the inconvenient husband."

Back to linux.debian.user | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread


Thread

Buster SSH Glenn English <ghe2001@gmail.com> - 2017-09-11 21:10 +0200
  Re: Buster SSH Cindy-Sue Causey <butterflybytes@gmail.com> - 2017-09-11 23:50 +0200
    Re: Buster SSH Glenn English <ghe2001@gmail.com> - 2017-09-12 00:40 +0200
      Re: Buster SSH "Alexander V. Makartsev" <avbetev@gmail.com> - 2017-09-12 01:20 +0200
        Re: Buster SSH Glenn English <ghe2001@gmail.com> - 2017-09-12 01:50 +0200
        Re: Buster SSH Glenn English <ghe2001@gmail.com> - 2017-09-12 19:50 +0200
          Re: Buster SSH Greg Wooledge <wooledg@eeg.ccf.org> - 2017-09-12 20:10 +0200
            Re: Buster SSH Glenn English <ghe2001@gmail.com> - 2017-09-12 22:00 +0200
            Re: Buster SSH Don Armstrong <don@debian.org> - 2017-09-13 17:40 +0200
              Re: Buster SSH Nicholas Geovanis <nickgeovanis@gmail.com> - 2017-09-13 19:30 +0200
                Re: Buster SSH Michael Stone <mstone@debian.org> - 2017-09-13 20:20 +0200
              Re: Buster SSH Glenn English <ghe2001@gmail.com> - 2017-09-13 19:40 +0200
            Re: Buster SSH Sven Hartge <sven@svenhartge.de> - 2017-09-14 00:30 +0200

csiph-web