Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.user > #186765
| From | Sven Hartge <sven@svenhartge.de> |
|---|---|
| Newsgroups | linux.debian.user |
| Subject | Re: Buster SSH |
| Date | 2017-09-14 00:30 +0200 |
| Message-ID | <upokp-4Sm-11@gated-at.bofh.it> (permalink) |
| References | (1 earlier) <uoEKC-rj-17@gated-at.bofh.it> <uoFwZ-16Z-5@gated-at.bofh.it> <uoG9I-1yX-13@gated-at.bofh.it> <uoXtU-4mv-1@gated-at.bofh.it> <uoXNf-4I9-19@gated-at.bofh.it> |
| Organization | Newsfeed am Wurmloch |
Greg Wooledge <wooledg@eeg.ccf.org> wrote: > On Tue, Sep 12, 2017 at 05:45:13PM +0000, Glenn English wrote: >> Bingo! User has dsa keys. Root has dsa and rsa keys. >> >> Thanks. Now all I have to do is figure out what I did so many years >> ago to generate the dsas :-) > You probably did ssh-keygen -t dsa. > There was a period of time, about 20 years ago, when DSA keys were > being promoted due to the RSA patent, which expired in 2000 in the US. > More recently, it has been learned that the DSA keys are "weak" > (citation needed), and so the recommendations have shifted. The core problem (as I understand it) of most DSA implementations is it depends on a perfect (P)RNG during operation. If your RNG is weak, an attacker could compute your private key just from observing your traffic (which the NSA for example does, as it has been proven). RSA on the other hand "only" needs a strong RNG during key creation but not during operation. Grüße, Sven. -- Sigmentation fault. Core dumped.
Back to linux.debian.user | Previous | Next — Previous in thread | Find similar | Unroll thread
Buster SSH Glenn English <ghe2001@gmail.com> - 2017-09-11 21:10 +0200
Re: Buster SSH Cindy-Sue Causey <butterflybytes@gmail.com> - 2017-09-11 23:50 +0200
Re: Buster SSH Glenn English <ghe2001@gmail.com> - 2017-09-12 00:40 +0200
Re: Buster SSH "Alexander V. Makartsev" <avbetev@gmail.com> - 2017-09-12 01:20 +0200
Re: Buster SSH Glenn English <ghe2001@gmail.com> - 2017-09-12 01:50 +0200
Re: Buster SSH Glenn English <ghe2001@gmail.com> - 2017-09-12 19:50 +0200
Re: Buster SSH Greg Wooledge <wooledg@eeg.ccf.org> - 2017-09-12 20:10 +0200
Re: Buster SSH Glenn English <ghe2001@gmail.com> - 2017-09-12 22:00 +0200
Re: Buster SSH Don Armstrong <don@debian.org> - 2017-09-13 17:40 +0200
Re: Buster SSH Nicholas Geovanis <nickgeovanis@gmail.com> - 2017-09-13 19:30 +0200
Re: Buster SSH Michael Stone <mstone@debian.org> - 2017-09-13 20:20 +0200
Re: Buster SSH Glenn English <ghe2001@gmail.com> - 2017-09-13 19:40 +0200
Re: Buster SSH Sven Hartge <sven@svenhartge.de> - 2017-09-14 00:30 +0200
csiph-web