Re: [Proftpd-user] signature type 'rsa-sha2-512' does not match publickey algorithm 'ssh-rsa'
"TJ Saunders" <[email protected]>
| Newsgroups | gmane.network.proftpd.user |
|---|---|
| Message-ID | <[email protected]> |
> > > > Why does "Session server hostkey" log "rsa-sha2-512" when all other logs that show successful logins have just Session server hostkey as "ssh-rsa" ? > > > > This is due to implementation of RFC 8332, which adds support for > > SHA2-512, to help transition away from SHA-1; see: > > https://github.com/proftpd/proftpd/issues/907 > > > > This SHA2-512 support requires client-side support as well -- and not > > all clients implement that support. Thus why the libssh-0.7.4 library > > may "work" (because it does not signal support for SHA2-512), but this > > newer libssh-0.9.0 library version may not. Perhaps there is a bug in > > the implementation in this library? > > > > In the mean time, you can configure mod_sftp to not try to use the > > "extension negotiation" mechanism to enable this SHA2-512 support, by > > using: > > > > SFTPOptions NoExtensionNegotation > > > > in your ProFTPD configuration; see: > > http://www.proftpd.org/docs/contrib/mod_sftp.html#SFTPOptions > > I used OpenSSH for the interoperability testing of this RSA-SHA2 > signature support. I'll try to reproduce this using libssh as well; it > is possible there is an issue with mod_sftp with this. Are you able to testing using _e.g._ libssh-0.9.5? I ask because I'm wondering if this relates to this particular libssh bug/commits: * https://bugs.libssh.org/T191 * https://bugs.libssh.org/rLIBSSH54cf7b92edf81cba34d97b6ea7253acb6b994298 Cheers, TJ _______________________________________________ ProFTPD Users List <[email protected]> Unsubscribe problems? http://www.proftpd.org/list-unsub.html