LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Slackware
User Name
Password
Slackware This Forum is for the discussion of Slackware Linux.

Notices


Reply
  Search this Thread
Old 01-27-2011, 07:24 AM   #1
shyko
LQ Newbie
 
Registered: Nov 2009
Location: Maríla, SP BRA
Distribution: Slackware
Posts: 4

Rep: Reputation: 1
ECDSA key generation


I'm not a master on ssh keys but it seems that with the last openssh update on -current:

Quote:
Thu Jan 27 01:53:26 UTC 2011
n/openssh-5.7p1-x86_64-1.txz: Upgraded.
The rc.sshd perhaps should include a command to generate a ECDSA key:

Code:
if [ ! -f /etc/ssh/ssh_host_ecdsa_key ]; then
    /usr/bin/ssh-keygen -t ecdsa -f /etc/ssh/ssh_host_ecdsa_key -N ''
fi
 
Old 01-28-2011, 01:40 AM   #2
ponce
LQ Guru
 
Registered: Aug 2004
Location: Pisa, Italy
Distribution: Slackware
Posts: 7,098

Rep: Reputation: 4175Reputation: 4175Reputation: 4175Reputation: 4175Reputation: 4175Reputation: 4175Reputation: 4175Reputation: 4175Reputation: 4175Reputation: 4175Reputation: 4175
if you do that, then ECDSA is used as the preferred key agreement algorithm when both the client and server support it.

I am personally just considering that:
- RSA served slackware, and more widely openssh, users by default for many years;
- looks like openbsd developers (many work on openssh too) were still cautious about the adoption of ECDSA as default four months ago;
- you can have situations like this;
- seeing it from the end user side, the decision of not generating the ECDSA keys, should have as a consequence just a simple warning when starting the daemon.

so, I think, it should be perfectly fine to ponder about it a little

Last edited by ponce; 01-28-2011 at 11:16 PM. Reason: typo
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
[SOLVED] Fedora 12 boots but get stuck at ssh1 host key generation Linuxnube88 Linux - General 9 03-25-2010 12:26 AM
OpenSSL DSA / ECDSA "EVP_VerifyFinal()" Spoofing Vulnerability win32sux Linux - Security 1 01-10-2009 04:56 PM
OpenVPN key generation chillster Linux - Security 1 12-22-2008 07:21 PM
gnupg key generation error! gabsik Linux - Security 0 02-28-2008 09:08 PM
Key Generation and Freeradius metallica1973 Linux - Software 1 11-27-2006 08:01 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Slackware

All times are GMT -5. The time now is 04:15 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration