Skip site navigation (1)Skip section navigation (2)
Date:      Fri, 26 Jul 2002 19:07:36 +0200
From:      Cedric Ware <cedric.ware@enst.fr>
To:        Dag-Erling Smorgrav <des@ofug.org>
Cc:        freebsd-security@freebsd.org
Subject:   Re: ssh host key inconsistency
Message-ID:  <20020726170736.GA16312@enst.fr>
In-Reply-To: <xzp8z3ymtm6.fsf@flood.ping.uio.no>
References:  <20020726135837.A7551@chiark.greenend.org.uk> <xzpd6tamynf.fsf@flood.ping.uio.no> <20020726145249.B7551@chiark.greenend.org.uk> <xzp8z3ymtm6.fsf@flood.ping.uio.no>

next in thread | previous in thread | raw e-mail | index | archive | help

> According to the draft standard, RSA is deprecated and DSA is the
> preferred cipher.

Do you have any references for this?  I have looked through
http://www.ietf.org/html.charters/secsh-charter.html, but I must
have missed it.

>  There's also a POLA issue; previous FreeBSD
> releases have used only DSA, and enabling RSA would cause spurious
> "unknown host key" warnings

Indeed.  (Although I am somewhat in the reverse situation, not being
a FreeBSD-only user...)

						Thank you,
						Cedric Ware.


To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?20020726170736.GA16312>