IETF-SSH archive

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]

Re: Fixing exchange of host keys in the SSH key exchange



OpenSSH documents this as a private extension:
 
 
Our SSH Server and Client do not implement this mechanism at this time, but it’s something I would like us to support.
 
denis
 
 
Sent: Monday, April 3, 2017 14:02
Subject: Re: Fixing exchange of host keys in the SSH key exchange
 
Hi,

if I may stick an oar in sideways: if you go to all the trouble,
could you add a mechanism by which the server could advise that
the host key used by the client was still valid but deprecated,
and to download the new host key once connected?

Speaking as an admin of a bunch of servers whose users -do- ask
when the host key changes, I currently feel a need for a better
mechanism for updates to longer keys than "send mail".

regards,
spz
--
spz%serpens.de@localhost (S.P.Zeidler)


Home | Main Index | Thread Index | Old Index