LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 05-11-2011, 03:16 PM   #1
sang_froid
Member
 
Registered: Oct 2006
Posts: 179

Rep: Reputation: 15
SSHD warning - using fixed modulus


Hi,

I am running a fresh installation of RHEL 6 box and it shipped with Openssh 5.3.

But, /etc/ssh/moduli file doesn't exist even in this new installation and the SSH log warns as below:

PHP Code:
WARNING: /etc/ssh/moduli does not existusing fixed modulus 
Does this imply that it is using the same random number for key exchange purpose ? Also, does it impose any security risks ??

Any ideas ???
 
Old 05-12-2011, 09:01 AM   #2
sundialsvcs
LQ Guru
 
Registered: Feb 2004
Location: SE Tennessee, USA
Distribution: Gentoo, LFS
Posts: 10,671
Blog Entries: 4

Rep: Reputation: 3945Reputation: 3945Reputation: 3945Reputation: 3945Reputation: 3945Reputation: 3945Reputation: 3945Reputation: 3945Reputation: 3945Reputation: 3945Reputation: 3945
See: man moduli.

The "Diffie-Hellman Key Exchange" is that point in the initial negotiation process where the two parties ("Alice" and "Bob") use public-key cipher techniques to negotiate and agree upon a random symmetric-cipher key that they will (initially...) use in their upcoming conversation. Part of that technique involves the use of large prime numbers. Some suitable numbers are built-in ("fixed"), but the moduli file allows you to pre-compute a list of candidate primes from which to randomly choose. I am not technically qualified to say what the total ramifications might be. But my uneducated opinion is that it is a choice between "strong," and "stronger yet."
 
Old 05-12-2011, 03:33 PM   #3
NyteOwl
Member
 
Registered: Aug 2008
Location: Nova Scotia, Canada
Distribution: Slackware, OpenBSD, others periodically
Posts: 512

Rep: Reputation: 139Reputation: 139
Not that you shouldn't ask here, but you paid for RHEL because it includes support. WHat did RH have to say?
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Starting sshd: /etc/init.d/sshd: line 113: /usr/sbin/sshd: Permission denied sumanc Linux - Server 5 03-28-2008 04:59 AM
Java Modulus operator freakyg Programming 3 06-06-2007 10:06 PM
bc: using -l messes up modulus Ephracis Programming 4 06-07-2005 01:34 PM
Divisibility without using modulus redhatrosh Programming 1 03-01-2005 10:02 PM
Modulus in Assembly How? browneyes Programming 2 10-07-2004 12:42 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 05:32 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration