Bug#1135120: openssh-server: generates ecdsa and ed25519 keys on security upgrade

Thorsten Glaser <[email protected]> Tue, 28 Jul 2026 22:38:28 +0200 (CEST)
Newsgroups gmane.linux.debian.devel.ssh
Message-ID <177c5418-c332-97e6-e241-265c55c15a34__24015.3264532395$1785271648$gmane$org@mirbsd.de>
On Tue, 28 Jul 2026, Colin Watson wrote:

> Nothing's changed here for a long time.  You can avoid this by
> explicitly setting HostKey in /etc/ssh/sshd_config or
> /etc/ssh/sshd_config/*.conf to only the host keys you want;
> openssh-server.postinst will respect that.

It=E2=80=99s interesting: it seems that if I set it in /etc/ssh/sshd_config
(as I used to), it is respected, but on the one system where this
happened, I had it in /etc/ssh/sshd_config.d/local.conf, where the
maintainer scripts, in contrast to the d=C3=A6mon itself, didn=E2=80=99t pi=
ck it
up; is this plausible?

bye,
//mirabilos
--=20
https://toot.mirbsd.org/@mirabilos/statuses/01KNQD9RNZM1Z2A61AZHG857MP
long list of references on why =E2=80=9CAI=E2=80=9D/LLMs are bad for everyo=
ne