Re: DH group exchange (Re: SSH key algorithm updates)

denis bider <[email protected]>
Newsgroups gmane.ietf.secsh
Message-ID <[email protected]>
Half the time - or even more often - the parameters sent by the server fail a pairwise consistency test that Crypto++ performs in FIPS mode.

I believe these tests are required by FIPS to use the crypto parameters.

I believe this has been recognized as a shortcoming of these dynamically generated groups, and has been deemed an acceptable level of risk because they are short-lived.

The issue is that FIPS (probably correctly, given its intent to prevent suspicious-looking crypto use) does not make this accommodation.


----- Original Message -----
From: Jeffrey Hutzelman 
Sent: Friday, November 6, 2015 21:50
To: denis bider 
Cc: [email protected] ; NielsMöller ; Mark D. Baushke ; [email protected] ; [email protected] ; [email protected] 
Subject: Re: DH group exchange (Re: SSH key algorithm updates)

On Sat, 2015-11-07 at 03:33 +0000, denis bider wrote:

> It is a fairly substantial problem that most dynamically generated
> groups aren't usable with our FIPS module.

What's broken about the groups that don't work?
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.