Re: Fixing exchange of host keys in the SSH key exchange
"denis bider \(Bitvise\)" <[email protected]> Tue, 4 Apr 2017 01:27:25 -0600
| Newsgroups | gmane.ietf.secsh |
|---|---|
| Message-ID | <05DC33124D144EC0B39A5BF58C8E3A33@Khan> |
OpenSSH documents this as a private extension: https://github.com/openssh/openssh-portable/blob/master/PROTOCOL#L286 Our SSH Server and Client do not implement this mechanism at this time, but it’s something I would like us to support. denis From: S.P.Zeidler Sent: Monday, April 3, 2017 14:02 To: denis bider (Bitvise) Cc: [email protected] ; [email protected] ; Simon Tatham Subject: Re: Fixing exchange of host keys in the SSH key exchange Hi, if I may stick an oar in sideways: if you go to all the trouble, could you add a mechanism by which the server could advise that the host key used by the client was still valid but deprecated, and to download the new host key once connected? Speaking as an admin of a bunch of servers whose users -do- ask when the host key changes, I currently feel a need for a better mechanism for updates to longer keys than "send mail". regards, spz -- [email protected] (S.P.Zeidler)