RE: rsa-sha2-256/512: handling of incorrect signature encoding

Peter Gutmann <[email protected]>
Newsgroups gmane.ietf.secsh
Message-ID <9A043F3CF02CD34C8E74AC1594475C73F4CDEE4D@uxcn10-5.UoA.auckland.ac.nz>
denis bider (Bitvise) <[email protected]> writes:

>I did set up a test server for the new rsa-sha2-XXX signature types; I posted
>connection information here, and included instructions to test both server and
>client authentication. I was under the impression that you might have used it,
>but I’m not sure if you did.

I did, but not for pubkey auth, for lack of a key to auth with.

Is it worth stating, in the draft, that if you use sha256 everywhere else then
you should also use it for pubkey auth?  I can't see any reason why you'd want
to use SHA-1 for that when you're using SHA-2 for everything else.  Then you
could also use the server's advertising SHA-2 to indicate that it'll take a
SHA-2 sig for auth.

Peter.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.