Re: Read host keys from environment variables

Philipp Marek via openssh-unix-dev <[email protected]>
Newsgroups gmane.network.openssh.devel
Message-ID <[email protected]>
>> One point I see here is that in case someone breaks into the 
>> container,
>> there's now a nicely defined API to fetch the host keys from,
> 
> No, the agent does not provide access to the raw keys.  It will sign
> challenges on your behalf, but it won't cough up the keys themselves.

Yeah, right, that's what I meant.


> You *could* probably pick the keys out of memory with a debugger
> (they're encrypted to mitigate rowhammer-style recovery attacks but a
> root-equivalent user could defeat that pretty easily).  That said, if
> you are in a position to do that to ssh-agent, you could just as
> easily do that to sshd itself.

Hmmm, host-keys in environment variables should do something similar 
then,
which makes the patch larger than +-10 lines ;/
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.