RE: SSH key algorithm updates
Peter Gutmann <[email protected]>
| Newsgroups | gmane.ietf.secsh |
|---|---|
| Message-ID | <9A043F3CF02CD34C8E74AC1594475C73F4B4BC9F@uxcn10-5.UoA.auckland.ac.nz> |
Jeffrey Hutzelman <[email protected]> writes: >- Add dsa-sha2-256 as RECOMMENDED I'm strongly opposed to keeping DSA, for the reasons given earlier. It's dead everywhere except SSH, it'd be nice to get rid of this one holdout as well. >Perhaps Denis wants to add pgp-sign-dsa-sha2-256 and/or x509v3-dsa-sha2-256 >to his document. Since neither the PGP nor the X.509 formats as used in SSH were ever defined, I'd just remove them. Short of reverse-engineering someone else's implementation to see what they do, I can't see how you'd create an interoperable implementation of either of these. Peter.