tech-security archive

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]

Re: Keys generated by "/etc/rc.d/sshd"



On Wed, May 28, 2008 at 06:44:50PM +0100, Matthias Scheler wrote:
> On Wed, May 28, 2008 at 09:36:57AM -0400, Greg Troxel wrote:
> > > Maybe keep it, but just not do it by default ?
> > 
> > How about if
> > 
> > sshd_generate_v1keys
> > 
> > is yes, then it makes v1 keys, and it defaults to no, or isn't in
> > defaults/rc.conf at all?
> 
> Why do we need a configuration setting? Creating a host key is a one-time
> operation. So the question is whether the user can be asked to run this
> command manually ...

Additionally we already have the config setting: in /etc/ssh/sshd_config.
I don't think we need a new rc.conf setting, parsing /etc/ssh/sshd_config
should be easy enough. But I agree that it may be overkill for a one-time
operation

-- 
Manuel Bouyer <bouyer%antioche.eu.org@localhost>
     NetBSD: 26 ans d'experience feront toujours la difference
--


Home | Main Index | Thread Index | Old Index