From owner-freebsd-bugs Sat Jun 2 2:35: 3 2001 Delivered-To: freebsd-bugs@freebsd.org Received: from obsecurity.dyndns.org (adsl-63-207-60-66.dsl.lsan03.pacbell.net [63.207.60.66]) by hub.freebsd.org (Postfix) with ESMTP id 9EE2137B424 for ; Sat, 2 Jun 2001 02:35:00 -0700 (PDT) (envelope-from kris@obsecurity.org) Received: by obsecurity.dyndns.org (Postfix, from userid 1000) id 323F9673A5; Sat, 2 Jun 2001 02:35:00 -0700 (PDT) Date: Sat, 2 Jun 2001 02:35:00 -0700 From: Kris Kennaway To: Archie Cobbs Cc: freebsd-bugs@FreeBSD.ORG Subject: Re: bin/27821: can't do RSA login via ssh to root account Message-ID: <20010602023500.F95359@xor.obsecurity.org> References: <200106012210.f51MA3V16636@freefall.freebsd.org> Mime-Version: 1.0 Content-Type: multipart/signed; micalg=pgp-md5; protocol="application/pgp-signature"; boundary="juZjCTNxrMaZdGZC" Content-Disposition: inline User-Agent: Mutt/1.2.5i In-Reply-To: <200106012210.f51MA3V16636@freefall.freebsd.org>; from archie@packetdesign.com on Fri, Jun 01, 2001 at 03:10:03PM -0700 Sender: owner-freebsd-bugs@FreeBSD.ORG Precedence: bulk List-ID: List-Archive: (Web Archive) List-Help: (List Instructions) List-Subscribe: List-Unsubscribe: X-Loop: FreeBSD.org --juZjCTNxrMaZdGZC Content-Type: text/plain; charset=us-ascii Content-Disposition: inline On Fri, Jun 01, 2001 at 03:10:03PM -0700, Archie Cobbs wrote: > Yep, the '-2' flag is what makes it work. Oh, maybe that makes sense, > I'm using a DSA key.. are they only supported by version 2? DSAAuthentication Specifies whether to try DSA authentication. The argument to this keyword must be ``yes'' or ``no''. DSA authentication will only be attempted if a DSA identity file exists. Note that this option applies to protocol version 2 only. > I thought that ssh+sshd would automatically negotiate version 2 but > maybe I assume too much. The default used to be to try protocol version 1 first; this has now changed to version 2 in the OpenSSH 2.9 client. It's always been configurable in your client configuration files. Kris --juZjCTNxrMaZdGZC Content-Type: application/pgp-signature Content-Disposition: inline -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.0.6 (FreeBSD) Comment: For info see http://www.gnupg.org iD8DBQE7GLNDWry0BWjoQKURAlIzAKCBx0qHshKB5SEy0g/b+EOOdzMQ3wCeMvZh Bk6XBed4QrKbV1zih+EOEqo= =kdIL -----END PGP SIGNATURE----- --juZjCTNxrMaZdGZC-- To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-bugs" in the body of the message