From owner-freebsd-stable@FreeBSD.ORG Fri Dec 2 23:39:31 2011 Return-Path: Delivered-To: stable@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id D8068106564A for ; Fri, 2 Dec 2011 23:39:31 +0000 (UTC) (envelope-from jdc@koitsu.dyndns.org) Received: from qmta13.emeryville.ca.mail.comcast.net (qmta13.emeryville.ca.mail.comcast.net [76.96.27.243]) by mx1.freebsd.org (Postfix) with ESMTP id BF81D8FC12 for ; Fri, 2 Dec 2011 23:39:31 +0000 (UTC) Received: from omta13.emeryville.ca.mail.comcast.net ([76.96.30.52]) by qmta13.emeryville.ca.mail.comcast.net with comcast id 4PFR1i00317UAYkADPfQPa; Fri, 02 Dec 2011 23:39:24 +0000 Received: from koitsu.dyndns.org ([67.180.84.87]) by omta13.emeryville.ca.mail.comcast.net with comcast id 4PdC1i01A1t3BNj8ZPdCcW; Fri, 02 Dec 2011 23:37:13 +0000 Received: by icarus.home.lan (Postfix, from userid 1000) id 6D7EA102C1D; Fri, 2 Dec 2011 15:39:30 -0800 (PST) Date: Fri, 2 Dec 2011 15:39:30 -0800 From: Jeremy Chadwick To: Freddie Cash Message-ID: <20111202233930.GA43590@icarus.home.lan> References: <20111202233220.GA43495@icarus.home.lan> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <20111202233220.GA43495@icarus.home.lan> User-Agent: Mutt/1.5.21 (2010-09-15) Cc: stable@freebsd.org Subject: Re: r228152: anyone got the None cipher working with base OpenSSH? X-BeenThere: freebsd-stable@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: Production branch of FreeBSD source code List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Fri, 02 Dec 2011 23:39:31 -0000 On Fri, Dec 02, 2011 at 03:32:20PM -0800, Jeremy Chadwick wrote: > There are multiple places where this needs to get defined for it to > work. Sorry I should be more clear (I woke up ~15 minutes ago). I'm referring to the fact that OpenSSH build points in FreeBSD are ""scattered all over"", e.g. src/secure/lib/libssh, src/secure/usr.bin/scp, src/secure/usr.bin/sftp, src/secure/usr.bin/ssh*, etc... You get the idea. The above make.conf addition will handle everything. And yes I have tested it. You also need to read README.hpn to understand fully how to get None cipher to work from the server AND client side, *AND* what the limits and caveats are. There are changes you need to make to /etc/ssh/sshd_config, and there are *multiple* -o switches you will need to use with the client (e.g. ssh -oCipher=none -oNoneEnabled=yes -oNoneSwitch=yes). If the WARNING message that is output to stderr bothers you, use -T. Good luck. -- | Jeremy Chadwick jdc at parodius.com | | Parodius Networking http://www.parodius.com/ | | UNIX Systems Administrator Mountain View, CA, US | | Making life hard for others since 1977. PGP 4BD6C0CB |