Re: Deprecating RSA ssh host keys in 16

Dag-Erling Smørgrav <[email protected]>
Newsgroups gmane.os.freebsd.architechture
Message-ID <[email protected]>
Colin Percival <[email protected]> writes:
> It's still a very helpful data point!  I've also had one response from
> someone with old IoT systems which only understand RSA host keys, so I
> think my proposed timeline of "warn people now that it will be disabled
> by default in 16" is the way to go.

Why is an IoT system making outbound ssh connections?  That's the only
way it would ever be aware of another system's host key.

Btw, I believe there is either a Bugzilla ticket or a Phabricator review
somewhere that makes the list of host key algorithms configurable (and
it's trivial to recreate if you can't find it).

Oh, and should we perhaps also disable (non-elliptic) DSA host keys?

DES
-- 
Dag-Erling Smørgrav - [email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.