Bug#1135120: marked as done (openssh-server: generates ecdsa and ed25519 keys on security upgrade)

"Debian Bug Tracking System" <[email protected]> Tue, 28 Jul 2026 12:59:03 +0000
Newsgroups gmane.linux.debian.devel.ssh
Message-ID <handler.1135120.D1135120.17852434382324327.ackdone@bugs.debian.org>
This is a multi-part message in MIME format...

------------=_1785243543-2325907-0
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain; charset="utf-8"

Your message dated Tue, 28 Jul 2026 13:57:15 +0100
with message-id <[email protected]>
and subject line Re: Bug#1135120: openssh-server: generates ecdsa and ed255=
19 keys on security upgrade
has caused the Debian Bug report #1135120,
regarding openssh-server: generates ecdsa and ed25519 keys on security upgr=
ade
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


--=20
1135120: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=3D1135120
Debian Bug Tracking System
Contact [email protected] with problems

------------=_1785243543-2325907-0
Content-Type: message/rfc822
Content-Disposition: inline
Content-Transfer-Encoding: 7bit

Received: (at submit) by bugs.debian.org; 27 Apr 2026 22:11:05 +0000
X-Spam-Checker-Version: SpamAssassin 4.0.1-bugs.debian.org_2005_01_02
	(2024-03-25) on buxtehude.debian.org
X-Spam-Level: 
X-Spam-Status: No, score=-18.9 required=4.0 tests=BAYES_00,
	BODY_INCLUDES_PACKAGE,FOURLA,HAS_PACKAGE,NO_RELAYS,XMAILER_REPORTBUG
	autolearn=ham autolearn_force=no
	version=4.0.1-bugs.debian.org_2005_01_02
X-Spam-Bayes: score:0.0000 Tokens: new, 21; hammy, 150; neutral, 111; spammy,
	0. spammytokens: hammytokens:0.000-+--XDebbugsCc,
	0.000-+--X-Debbugs-Cc, 0.000-+--HTo:N*Debian, 0.000-+--H*Ad:N*Bug,
	0.000-+--H*Ad:N*Tracking
Return-path: <[email protected]>
Received: via submission
	by buxtehude.debian.org with esmtp (Exim 4.96)
	(envelope-from <[email protected]>)
	id 1wHUAS-007ICv-0w
	for [email protected];
	Mon, 27 Apr 2026 22:11:05 +0000
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: Thorsten Glaser <[email protected]>
To: Debian Bug Tracking System <[email protected]>
Subject: openssh-server: generates ecdsa and ed25519 keys on security upgrade
Message-ID: <[email protected]>
X-Mailer: reportbug 7.10.3+deb11u2
Date: Mon, 27 Apr 2026 22:11:01 +0000
Delivered-To: [email protected]

Package: openssh-server
Version: 1:8.4p1-5+deb11u6
Severity: normal
X-Debbugs-Cc: [email protected], [email protected]

There recently was an OpenSSH upgrade, which led to it
generating ecdsa and ed25519 keys I had deliberately
removed because I use only RSA keys.



-- System Information:
Debian Release: 11.11
  APT prefers oldoldstable-updates
  APT policy: (500, 'oldoldstable-updates'), (500, 'oldoldstable-security'), (500, 'oldoldstable')
Architecture: amd64 (x86_64)
Foreign Architectures: i386

Kernel: Linux 5.10.0-39-amd64 (SMP w/1 CPU thread)
Locale: LANG=C.UTF-8, LC_CTYPE=C.UTF-8 (charmap=UTF-8), LANGUAGE not set
Shell: /bin/sh linked to /bin/lksh
Init: sysvinit (via /sbin/init)

Versions of packages openssh-server depends on:
ii  adduser                3.118+deb11u1
ii  debconf [debconf-2.0]  1.5.77
ii  dpkg                   1.20.13
ii  libaudit1              1:3.0-2
ii  libc6                  2.31-13+deb11u13
ii  libcom-err2            1.46.2-2+deb11u1
ii  libcrypt1              1:4.4.18-4
ii  libgssapi-krb5-2       1.18.3-6+deb11u7
ii  libkrb5-3              1.18.3-6+deb11u7
ii  libpam-modules         1.4.0-9+deb11u2
ii  libpam-runtime         1.4.0-9+deb11u2
ii  libpam0g               1.4.0-9+deb11u2
ii  libselinux1            3.1-3
ii  libssl1.1              1.1.1w-0+deb11u5
ii  libsystemd0            247.3-7+deb11u8
ii  libwrap0               7.6.q-31
ii  lsb-base               11.1.0
ii  openssh-client         1:8.4p1-5+deb11u6
ii  openssh-sftp-server    1:8.4p1-5+deb11u6
ii  procps                 2:3.3.17-5
ii  runit-helper           2.10.3
ii  ucf                    3.0043+deb11u2
ii  zlib1g                 1:1.2.11.dfsg-2+deb11u2

Versions of packages openssh-server recommends:
ii  logind-considered-harmful [logind]  89
pn  ncurses-term                        <none>
pn  xauth                               <none>

Versions of packages openssh-server suggests:
ii  molly-guard   0.7.2
pn  monkeysphere  <none>
pn  ssh-askpass   <none>
pn  ufw           <none>

-- debconf information:
  openssh-server/password-authentication: true
  openssh-server/permit-root-login: true

------------=_1785243543-2325907-0
Content-Type: message/rfc822
Content-Disposition: inline
Content-Transfer-Encoding: 7bit

Received: (at 1135120-close) by bugs.debian.org; 28 Jul 2026 12:57:18 +0000
X-Spam-Checker-Version: SpamAssassin 4.0.1-bugs.debian.org_2005_01_02
	(2024-03-25) on buxtehude.debian.org
X-Spam-Level: 
X-Spam-Status: No, score=-110.8 required=4.0 tests=BAYES_00,DKIMWL_WL_HIGH,
	DKIM_SIGNED,DKIM_VALID,DKIM_VALID_AU,DKIM_VALID_EF,FROMDEVELOPER,
	HAS_BUG_NUMBER,SPF_HELO_NONE,SPF_PASS,USER_IN_DKIM_WELCOMELIST
	autolearn=ham autolearn_force=no
	version=4.0.1-bugs.debian.org_2005_01_02
X-Spam-Bayes: score:0.0000 Tokens: new, 14; hammy, 150; neutral, 37; spammy,
	0. spammytokens:
	hammytokens:0.000-+--Hx-spam-relays-external:sk:stravin,
	0.000-+--H*RT:sk:stravin, 0.000-+--Hx-spam-relays-external:311,
	0.000-+--H*RT:311, 0.000-+--H*RT:108
Return-path: <[email protected]>
Received: from stravinsky.debian.org ([2001:41b8:202:deb::311:108]:41234)
	by buxtehude.debian.org with esmtps (TLS1.3:ECDHE_SECP256R1__RSA_PSS_RSAE_SHA256__AES_256_GCM:256)
	(Exim 4.96)
	(envelope-from <[email protected]>)
	id 1wohN0-009kez-1y
	for [email protected];
	Tue, 28 Jul 2026 12:57:18 +0000
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=debian.org;
	s=smtpauto.stravinsky; h=X-Debian-User:In-Reply-To:Content-Type:MIME-Version:
	References:Message-ID:Subject:To:From:Date:Reply-To:Cc:
	Content-Transfer-Encoding:Content-ID:Content-Description;
	bh=QYGPt/XHK/GI7dBW+1dTRZE4IWyXLXLY95riKXbaN2Q=; b=XMiZxmdpDa0ttNvhal8ctY3Xff
	3evCIw/C9c6L8Iv1RiKZ/FmcthsPq4M6yy9dBDvQg+teqp80MNZcscWraM4YlyxTa5A/tDyWaknWY
	hxLxeFvwAUaQG89Gdxef8pTStwykJ0ISr5YQkxHm8KxOOVM5+1QaeE1GpYtcZuLyspL79Zs5k9bN3
	2EJ6HgaSQoj5FVpZdO85GyvnsLgFLLJO/DgTfS0fpP77Z4l7MQ+OG0Iy1IhiUpqR1EcEdGyx2a2Gb
	PnY3GWEuJHdoCgekon8jj1cMmPgdw5o5PlP3Frt9XDgrLQezFUlWK8DCghoefYmmyT04kJfolNcWV
	r++lIE3g==;
Received: from authenticated-user
	by stravinsky.debian.org with esmtpsa (TLS1.3:ECDHE_SECP256R1__RSA_PSS_RSAE_SHA256__AES_256_GCM:256)
	(Exim 4.96)
	(envelope-from <[email protected]>)
	id 1wohMz-007gr0-0E;
	Tue, 28 Jul 2026 12:57:17 +0000
Received: from ns1.rosewood.vpn.ucam.org ([172.20.153.2] helo=riva.ucam.org)
	by riva.rosewood.vpn.ucam.org with esmtps  (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384
	(Exim 4.98.2)
	(envelope-from <[email protected]>)
	id 1wohMy-00000009Y4X-2a5W;
	Tue, 28 Jul 2026 13:57:16 +0100
Date: Tue, 28 Jul 2026 13:57:15 +0100
From: Colin Watson <[email protected]>
To: Thorsten Glaser <[email protected]>, [email protected]
Subject: Re: Bug#1135120: openssh-server: generates ecdsa and ed25519 keys on
 security upgrade
Message-ID: <[email protected]>
References: <[email protected]>
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii; format=flowed
Content-Disposition: inline
In-Reply-To: <[email protected]>
X-Debian-User: cjwatson

On Mon, Apr 27, 2026 at 10:11:01PM +0000, Thorsten Glaser wrote:
>Package: openssh-server
>Version: 1:8.4p1-5+deb11u6
>Severity: normal
>X-Debbugs-Cc: [email protected], [email protected]
>
>There recently was an OpenSSH upgrade, which led to it
>generating ecdsa and ed25519 keys I had deliberately
>removed because I use only RSA keys.

Nothing's changed here for a long time.  You can avoid this by 
explicitly setting HostKey in /etc/ssh/sshd_config or 
/etc/ssh/sshd_config/*.conf to only the host keys you want; 
openssh-server.postinst will respect that.

Thanks,