Skip site navigation (1)Skip section navigation (2)
Date:      Wed, 3 Sep 2008 00:43:18 +0000 (UTC)
From:      "Bjoern A. Zeeb" <bzeeb-lists@lists.zabbadoz.net>
To:        Dag-Erling Smorgrav <des@FreeBSD.org>
Cc:        cvs-src@FreeBSD.org, src-committers@FreeBSD.org, cvs-all@FreeBSD.org
Subject:   Re: cvs commit: src UPDATING
Message-ID:  <20080903002453.I65801@maildrop.int.zabbadoz.net>
In-Reply-To: <200809012355.m81NtjZT038288@repoman.freebsd.org>
References:  <200809012355.m81NtjZT038288@repoman.freebsd.org>

next in thread | previous in thread | raw e-mail | index | archive | help
On Mon, 1 Sep 2008, Dag-Erling Smorgrav wrote:

Hi,

> des         2008-09-01 23:50:56 UTC
>
>  FreeBSD src repository
>
>  Modified files:
>    .                    UPDATING
>  Log:
>  SVN rev 182662 on 2008-09-01 23:50:56Z by des
>
>  Belatedly add a notice about the reversed order of preference for OpenSSH
>  authentication keys.

So I had an updated ssh client in use since at least Aug 22 and it
didn't bother me to ask about any remote machines.

Now that people are updating their 7-STABLE machines, those 7-STABLE
machines with an OpenSSH 5.1p1 start to pop up and do the DSA vs. RSA
fingerprint dance for the host keys (at least until I added this to
line 1 of my ~/.ssh/config as hinted with this UPDATING entry:
 	HostKeyAlgorithms ssh-dss,ssh-rsa
).

To my understanding this should have happened 10 days ago to me.
I wonder why the peer needs to be updated as well for this?

Is this because sshds up to now only advertised dss (also on stable)
and with the update to 5.1p1 start to advertise rsa,dss and with the
updated client rsa matches?

In that case that would mean that stable users would see that as well?
Or at least STABLE sshds would behave different on new clients?
That could potentially break auto-pilot setups for people on the
stable branch?


/bz, highly confused (and tired)

-- 
Bjoern A. Zeeb              Stop bit received. Insert coin for new game.



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?20080903002453.I65801>