From owner-svn-src-head@freebsd.org Mon Aug 8 10:41:02 2016 Return-Path: Delivered-To: svn-src-head@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id 3766FBB2E72; Mon, 8 Aug 2016 10:41:02 +0000 (UTC) (envelope-from bms@fastmail.net) Received: from out2-smtp.messagingengine.com (out2-smtp.messagingengine.com [66.111.4.26]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client did not present a certificate) by mx1.freebsd.org (Postfix) with ESMTPS id 0943F1A30; Mon, 8 Aug 2016 10:41:01 +0000 (UTC) (envelope-from bms@fastmail.net) Received: from compute2.internal (compute2.nyi.internal [10.202.2.42]) by mailout.nyi.internal (Postfix) with ESMTP id A024A20559; Mon, 8 Aug 2016 06:41:00 -0400 (EDT) Received: from frontend2 ([10.202.2.161]) by compute2.internal (MEProxy); Mon, 08 Aug 2016 06:41:00 -0400 DKIM-Signature: v=1; a=rsa-sha1; c=relaxed/relaxed; d=fastmail.net; h=cc :content-transfer-encoding:content-type:date:from:in-reply-to :message-id:mime-version:references:subject:to:x-sasl-enc :x-sasl-enc; s=mesmtp; bh=/l57hXfRUL5s5G7Oa5yQlr5uHk4=; b=kyaT2v lbtPy9d958GzeB+oNrpChpPQnOOwPpXnseIiXtV4FBXuNloGKXTCXS+h8UHULqCJ nCa0hKPRXZdEeEtGtgaflH+UjSliJ6Ckq1qzoV3jMxkRmwnOa4qA8tAgqoOrh1CY +WWFAuJwDruxtMI6oMt9+uPkQEofgw9mdF6Lk= DKIM-Signature: v=1; a=rsa-sha1; c=relaxed/relaxed; d= messagingengine.com; h=cc:content-transfer-encoding:content-type :date:from:in-reply-to:message-id:mime-version:references :subject:to:x-sasl-enc:x-sasl-enc; s=smtpout; bh=/l57hXfRUL5s5G7 Oa5yQlr5uHk4=; b=pAXNlSMCtWRYPrO6dYQjIegtdKXLiO+Pp669oWftKWzVJsG YIbwLCB+ZfzNOBtUCMBTZY/fvCjjrNfAfrwjg5NXqA45xXi7+fTZfQPdOsHvNnj8 1vpC2Fh9B2M0IcGknIleiPaPJdVMDreUL+KDP9vkJPG7NDjDaxd3qwkRcomU= X-Sasl-enc: PznuKUwDQS13nC70tc1w96IEnrGZBiFvey6K6PI/vBN2 1470652860 Received: from pion.local (5751ac42.skybroadband.com [87.81.172.66]) by mail.messagingengine.com (Postfix) with ESMTPA id F1F40CCE66; Mon, 8 Aug 2016 06:40:58 -0400 (EDT) Subject: Re: svn commit: r303716 - head/crypto/openssh To: =?UTF-8?Q?Dag-Erling_Sm=c3=b8rgrav?= References: <201608031608.u73G8Mjq055909@repo.freebsd.org> <9a01870a-d99d-13a2-54bd-01d32616263c@fastmail.net> <30e655d1-1df7-5e2a-fccb-269e3cea4684@freebsd.org> <20160807125227.GC22212@zxy.spb.ru> <7237f5e6-fd65-a7e5-7751-4ed1c464b39a@freebsd.org> <4D28752C-0584-4294-9250-FA88B0C6E805@bsdimp.com> <86zionv96s.fsf@desk.des.no> Cc: Warner Losh , Andrey Chernov , Slawa Olhovchenkov , Oliver Pinter , svn-src-head@freebsd.org, svn-src-all@freebsd.org, src-committers@freebsd.org From: Bruce Simpson Message-ID: <208bd6bd-ec11-b9f6-ecb8-6b3fb772c331@fastmail.net> Date: Mon, 8 Aug 2016 11:40:55 +0100 User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:45.0) Gecko/20100101 Thunderbird/45.2.0 MIME-Version: 1.0 In-Reply-To: <86zionv96s.fsf@desk.des.no> Content-Type: text/plain; charset=utf-8; format=flowed Content-Transfer-Encoding: 8bit X-BeenThere: svn-src-head@freebsd.org X-Mailman-Version: 2.1.22 Precedence: list List-Id: SVN commit messages for the src tree for head/-current List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 08 Aug 2016 10:41:02 -0000 On 08/08/16 11:36, Dag-Erling Smørgrav wrote: > Bruce Simpson writes: >> Alcatel-Lucent OmniSwitch 6800 login broken ... > This patch did not remove weak DH groups. That happened in 7.0p1 back > in January. So my reading of this is that PuTTy may be the best workaround for end-users who have to speak to older SSH implementations. That's what I ended up using to get around some of the SSH interop mess with the Proxim AP4000, although much of that was not directly related to the cipher suite! (But ideally it should support X11-headless operation. To my knowledge, and as others have mentioned, it is currently believed to require it.)