Re: [Proftpd-user] signature type 'rsa-sha2-512' does not match publickey algorithm 'ssh-rsa'
"TJ Saunders" <[email protected]>
| Newsgroups | gmane.network.proftpd.user |
|---|---|
| Message-ID | <[email protected]> |
> > Why does "Session server hostkey" log "rsa-sha2-512" when all other logs that show successful logins have just Session server hostkey as "ssh-rsa" ? This is due to implementation of RFC 8332, which adds support for SHA2-512, to help transition away from SHA-1; see: https://github.com/proftpd/proftpd/issues/907 This SHA2-512 support requires client-side support as well -- and not all clients implement that support. Thus why the libssh-0.7.4 library may "work" (because it does not signal support for SHA2-512), but this newer libssh-0.9.0 library version may not. Perhaps there is a bug in the implementation in this library? In the mean time, you can configure mod_sftp to not try to use the "extension negotiation" mechanism to enable this SHA2-512 support, by using: SFTPOptions NoExtensionNegotation in your ProFTPD configuration; see: http://www.proftpd.org/docs/contrib/mod_sftp.html#SFTPOptions Hope this helps, TJ _______________________________________________ ProFTPD Users List <[email protected]> Unsubscribe problems? http://www.proftpd.org/list-unsub.html