DaemonForums  

Go Back   DaemonForums > DaemonForums.org > News

News News regarding BSD and related.

Reply
 
Thread Tools Display Modes
  #1   (View Single Post)  
Old 1st February 2015
J65nko J65nko is offline
Administrator
 
Join Date: May 2008
Location: Budel - the Netherlands
Posts: 4,132
Default OpenSSH Will Feature Key Discovery and Rotation For Easier Switching To Ed25519

From http://it.slashdot.org/story/15/02/0...ing-to-ed25519

Quote:
OpenSSH developer Damien Miller has posted about a new feature he implemented and committed for the next upcoming 6.8 release of OpenSSH — hostkeys@openssh.com — an OpenSSH extension to the SSH protocol for sshd to automatically send all of its public keys to the client, and for the client to automatically replace all keys of such server within ~/.ssh/known_hosts with the fresh copies as supplied (provided the server is trusted in the first place, of course). The protocol extension is simple enough, and is aimed to make it easier to switch over from DSA to the OpenSSL-free Ed25519 public keys. It is also designed in such a way as to support the concept of spare host keys being stored offline, which could then seamlessly replace main active keys should they ever become compromised.
The link to the blog : http://blog.djm.net.au/2015/02/key-r...penssh-68.html

Info about Ed25519 : http://en.wikipedia.org/wiki/EdDSA and http://ed25519.cr.yp.to
__________________
You don't need to be a genius to debug a pf.conf firewall ruleset, you just need the guts to run tcpdump

Last edited by J65nko; 1st February 2015 at 06:29 PM.
Reply With Quote
Reply

Tags
ed25519, openssh, ssh key rotation


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
[Solved] VIM without Python feature ? sw2wolf OpenBSD Packages and Ports 3 14th May 2012 01:14 AM
MINIX 3.2.0 makes porting easier, introduces FUSE support J65nko News 0 29th February 2012 11:21 PM
Guardian switching from Java to Scala J65nko News 0 5th April 2011 09:39 PM
Disappearing firefox feature.. BSDfan666 OpenBSD Packages and Ports 7 2nd November 2008 03:47 PM
Qs for switching from Ubuntu to OpenBSD JavaUser OpenBSD General 5 17th October 2008 11:28 AM


All times are GMT. The time now is 07:28 PM.


Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.
Content copyright © 2007-2010, the authors
Daemon image copyright ©1988, Marshall Kirk McKusick