Skip site navigation (1)Skip section navigation (2)
Date:      Wed, 3 Sep 2008 09:47:20 +0000 (UTC)
From:      "Bjoern A. Zeeb" <bzeeb-lists@lists.zabbadoz.net>
To:        =?utf-8?Q?Dag-Erling_Sm=C3=B8rgrav?= <des@des.no>
Cc:        cvs-src@FreeBSD.org, src-committers@FreeBSD.org, cvs-all@FreeBSD.org
Subject:   Re: cvs commit: src UPDATING
Message-ID:  <20080903094624.I65801@maildrop.int.zabbadoz.net>
In-Reply-To: <86ej41d0q4.fsf@ds4.des.no>
References:  <200809012355.m81NtjZT038288@repoman.freebsd.org> <20080903002453.I65801@maildrop.int.zabbadoz.net> <86ej41d0q4.fsf@ds4.des.no>

next in thread | previous in thread | raw e-mail | index | archive | help
  This message is in MIME format.  The first part should be readable text,
  while the remaining parts are likely unreadable without MIME-aware tools.

--0-798662833-1220435240=:65801
Content-Type: TEXT/PLAIN; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: QUOTED-PRINTABLE

On Wed, 3 Sep 2008, Dag-Erling Sm=F8rgrav wrote:

Hi,

> "Bjoern A. Zeeb" <bzeeb-lists@lists.zabbadoz.net> writes:
>> So I had an updated ssh client in use since at least Aug 22 and it
>> didn't bother me to ask about any remote machines.
>>
>> Now that people are updating their 7-STABLE machines, those 7-STABLE
>> machines with an OpenSSH 5.1p1 start to pop up and do the DSA vs. RSA
>> fingerprint dance for the host keys (at least until I added this to
>> line 1 of my ~/.ssh/config as hinted with this UPDATING entry:
>> =09HostKeyAlgorithms ssh-dss,ssh-rsa
>> ).
>>
>> To my understanding this should have happened 10 days ago to me.
>> I wonder why the peer needs to be updated as well for this?
>
> Because older servers don't have RSA keys (or rather, they don't load
> them).  Instead of just inverting the order, whoever decided that we
> should prefer DSA to RSA (before my time) just removed the two lines of
> code that load the RSA key.
>
> 8 will load both RSA and DSA keys, as intended.  So will 7, but that was
> actually a mis-merge on my part.  I will revert it as soon as I get
> re@'s approval.

Ah, makes much more sense now. Thanks for explaining (and fixing in 7:)

/bz

--=20
Bjoern A. Zeeb              Stop bit received. Insert coin for new game.
--0-798662833-1220435240=:65801--



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?20080903094624.I65801>