GNU bug report logs

#44887 openssh service creates DSA keys

PackageSource(s)Maintainer(s)
guix PTS Buildd Popcon
Full log

Message #13 received at 44887@debbugs.gnu.org (full text, mbox, reply):

Received: (at 44887) by debbugs.gnu.org; 19 Jun 2024 12:03:18 +0000
From debbugs-submit-bounces@debbugs.gnu.org Wed Jun 19 08:03:18 2024
Received: from localhost ([127.0.0.1]:41496 helo=debbugs.gnu.org)
	by debbugs.gnu.org with esmtp (Exim 4.84_2)
	(envelope-from <debbugs-submit-bounces@debbugs.gnu.org>)
	id 1sJu22-0005tY-4N
	for submit@debbugs.gnu.org; Wed, 19 Jun 2024 08:03:18 -0400
Received: from mail-wr1-f43.google.com ([209.85.221.43]:54677)
 by debbugs.gnu.org with esmtp (Exim 4.84_2)
 (envelope-from <efraim.flashner@gmail.com>) id 1sJu1z-0005tI-H7
 for 44887@debbugs.gnu.org; Wed, 19 Jun 2024 08:03:17 -0400
Received: by mail-wr1-f43.google.com with SMTP id
 ffacd0b85a97d-35f1bc2ab37so5836221f8f.1
 for <44887@debbugs.gnu.org>; Wed, 19 Jun 2024 05:03:12 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
 d=gmail.com; s=20230601; t=1718798526; x=1719403326; darn=debbugs.gnu.org;
 h=in-reply-to:content-disposition:mime-version:references
 :mail-followup-to:message-id:subject:cc:to:from:date:sender:from:to
 :cc:subject:date:message-id:reply-to;
 bh=4Lt4C0CAqNvh4UdVRMkRdI2HCXq+NZ9fkXaDQnh2Hv8=;
 b=lWCNUg6ItFgXaZwNIpv9p04VB/dqenJiaI1qhrlkK4hTAFKmHiw/oVGHU4J1z9kcDD
 tuOUXJ/odmFy7ilzBSLz0hj4+afa5GxEWi46wdgQ2IZy9b19x1OZA7MmUpRNlP3JS5xm
 yttQWDueVOuwZOK/GDNLPHUKn2qdVLtqsZCdJhu9DtuRHraWKhspRPoiArbM8058ELdK
 8YP5yntQdX3aSu55fWOpkCowDhoN62kY+mGBWBmjTQI2BKpa1/1Gtl3AGrIEHaYHUozR
 /x3g41I3ZE8mthtPiE1I1IcY1zsUdo8coIYt0JoT7ygj9jHFtZsBSqFHtOdcHDJUbMSE
 gIlA==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
 d=1e100.net; s=20230601; t=1718798526; x=1719403326;
 h=in-reply-to:content-disposition:mime-version:references
 :mail-followup-to:message-id:subject:cc:to:from:date:sender
 :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to;
 bh=4Lt4C0CAqNvh4UdVRMkRdI2HCXq+NZ9fkXaDQnh2Hv8=;
 b=pL0ADmU3TAcVZVP3eU8F58r10y29sunnk7gLEF2PH2SEgPCc8PMVo0eyIndqtpIocc
 mGQ7XoSO2yt/6sTpM6rYwTbCgXLXQY79kxQB75lUDfe55jba0EoVmPw1ZoA2Ja20KMG/
 C2a7v9OioJ2bC0MU4Jo202RdaGNAgq0jtlnVnwt7EpfhSmT6i4X/BvJP/yLyZG62a3UI
 IVVySEx8LqKPJ0+xz5vd8eeIO65Q52JFNOGKg+9zYB9McWGeJOEIxJQu+zx6SCBqpyi1
 //RdUSomiC35/I+ZX5unOjpUhFsVD6I7op9VlzxaNkI8uZmP9SC6jeac3TrUie9clApo
 Cgog==
X-Forwarded-Encrypted: i=1;
 AJvYcCU2oRaLPVmv4QHIGW8t1ApUyejDDUEwy66j5bRu4cWWspulf1OpDgYSgS7sTAN2luMZFcsm3FedRI25ZilXKEV6cga9e/s=
X-Gm-Message-State: AOJu0YyG6mGhP69nHuKlykUnFTfrZMlegXehs94rtKsahpiIm/gznegu
 c194SUDjodaZJOXqk8p9g6BagocQVWLhclvpiW9xoAOaX1IHkvkg
X-Google-Smtp-Source: AGHT+IFQ/Ncjs5q88pDwDcg80BrYDBC4r6odmFnPfbYhP2xSJTPgKMpg5jpwq48ISoIlALqM3kiULg==
X-Received: by 2002:adf:e78a:0:b0:362:41a4:974e with SMTP id
 ffacd0b85a97d-363175b8f6bmr1497369f8f.16.1718798526067; 
 Wed, 19 Jun 2024 05:02:06 -0700 (PDT)
Received: from localhost ([94.230.83.168]) by smtp.gmail.com with ESMTPSA id
 ffacd0b85a97d-363a23143dfsm1438203f8f.87.2024.06.19.05.02.05
 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256);
 Wed, 19 Jun 2024 05:02:05 -0700 (PDT)
Date: Wed, 19 Jun 2024 15:02:04 +0300
From: Efraim Flashner <efraim@flashner.co.il>
To: Vincent Legoll <vincent.legoll@gmail.com>
Subject: Re: openssh service creates DSA keys
Message-ID: <ZnLIvD7i4_SGsjB7@3900XT>
Mail-Followup-To: Efraim Flashner <efraim@flashner.co.il>,
 Vincent Legoll <vincent.legoll@gmail.com>,
 Ludovic Courtès <ludo@gnu.org>,
 44887@debbugs.gnu.org
References: <CAEwRq=rU2wD7ZzcjnTJ0+1DAP6TVE+aytqCKxCbLg0KRjnqn9Q@mail.gmail.com>
MIME-Version: 1.0
Content-Type: multipart/signed; micalg=pgp-sha256;
 protocol="application/pgp-signature"; boundary="lYMRkEmB1j5MhHvo"
Content-Disposition: inline
In-Reply-To: <CAEwRq=rU2wD7ZzcjnTJ0+1DAP6TVE+aytqCKxCbLg0KRjnqn9Q@mail.gmail.com>
X-PGP-Key-ID: 0x41AAE7DCCA3D8351
X-PGP-Key: https://flashner.co.il/~efraim/efraim_flashner.asc
X-PGP-Fingerprint: A28B F40C 3E55 1372 662D  14F7 41AA E7DC CA3D 8351
X-Spam-Score: 0.2 (/)
X-Debbugs-Envelope-To: 44887
Cc: 44887@debbugs.gnu.org, Ludovic Courtès <ludo@gnu.org>
X-BeenThere: debbugs-submit@debbugs.gnu.org
X-Mailman-Version: 2.1.18
Precedence: list
List-Id: <debbugs-submit.debbugs.gnu.org>
List-Unsubscribe: <https://debbugs.gnu.org/cgi-bin/mailman/options/debbugs-submit>, 
 <mailto:debbugs-submit-request@debbugs.gnu.org?subject=unsubscribe>
List-Archive: <https://debbugs.gnu.org/cgi-bin/mailman/private/debbugs-submit/>
List-Post: <mailto:debbugs-submit@debbugs.gnu.org>
List-Help: <mailto:debbugs-submit-request@debbugs.gnu.org?subject=help>
List-Subscribe: <https://debbugs.gnu.org/cgi-bin/mailman/listinfo/debbugs-submit>, 
 <mailto:debbugs-submit-request@debbugs.gnu.org?subject=subscribe>
Errors-To: debbugs-submit-bounces@debbugs.gnu.org
Sender: "Debbugs-submit" <debbugs-submit-bounces@debbugs.gnu.org>
X-Spam-Score: -0.8 (/)
[Message part 1 (text/plain, inline)]
On Tue, Jun 18, 2024 at 07:28:35PM +0000, Vincent Legoll wrote:
> Hello,
> 
> I've done some digging on that issue. Hope it'll help.
> 
> It looks like the clients still support the DSA keys.
> 
> This is on a Void linux desktop:
> 
> [vince@destop ~]$ ssh -Q PubkeyAcceptedAlgorithms | grep -i dss
> ssh-dss
> ssh-dss-cert-v01@openssh.com
> 
> The following Guix VM has been created 2 days ago, with a very light config
> 
> vince@guix ~$ ssh -Q PubkeyAcceptedAlgorithms | grep -i ssh-dss
> ssh-dss
> ssh-dss-cert-v01@openssh.com
> 
> So, I created a DSA PKI key pair, like so:
> 
> ssh-keygen -N '' -t dsa -f ssh-key-dsa
> 
> Uploaded the public key to the guix VM, as ~vince/.ssh/authorized_keys
> then tried to connect to the OpenSSH server on that VM
> 
> [vince@desktop ~]$ ssh -vi ssh-key-dsa vince@10.0.0.101
> OpenSSH_9.7p1, OpenSSL 3.3.0 9 Apr 2024
> debug1: Reading configuration data /home/vince/.ssh/config
> debug1: /home/vince/.ssh/config line 1: Applying options for *
> debug1: Reading configuration data /etc/ssh/ssh_config
> debug1: Connecting to 10.0.0.101 [10.0.0.101] port 22.
> debug1: Connection established.
> debug1: identity file ssh-key-dsa type 1
> [...]
> debug1: Skipping ssh-dss key ssh-key-dsa - corresponding algorithm not
> in PubkeyAcceptedAlgorithms
> debug1: No more authentication methods to try.
> vince@10.0.0.101: Permission denied (publickey).
> 
> So it looks like DSA client keys are not accepted any more by default.
> 
> Is there a problem for the server host key ?
> 
> vince@guix ~$ ls /etc/ssh/
> authorized_keys.d/      ssh_host_ed25519_key      ssh_host_rsa_key.pub
> ssh_host_ecdsa_key      ssh_host_ed25519_key.pub
> ssh_host_ecdsa_key.pub  ssh_host_rsa_key
> 
> No DSA keys here. Maybe something has been changed and they are not
> created any more.
> 
> So I'm not sure there is a problem, or am I mistaken ?
> Didn't I look hard enough ?
> 
> WDYT ?
> 
> Announce of DSA support removal from OpenSSH:
> https://lists.mindrot.org/pipermail/openssh-unix-dev/2024-January/041132.html
> 
> Some context about DSA keys:
> https://security.stackexchange.com/questions/112802/why-openssh-deprecated-dsa-keys

It looks like openssh, at some point in the past <period-of-time>,
stopped creating host DSA keys by default. Given the original bug report
was that DSA keys were created by default and now they're not I think we
can close this bug now.

Any objections?

-- 
Efraim Flashner   <efraim@flashner.co.il>   רנשלפ םירפא
GPG key = A28B F40C 3E55 1372 662D  14F7 41AA E7DC CA3D 8351
Confidentiality cannot be guaranteed on emails sent or received unencrypted
[signature.asc (application/pgp-signature, inline)]

Send a report that this bug log contains spam.


debbugs.gnu.org maintainers <help-debbugs@gnu.org>. Last modified: Sun Dec 22 02:18:45 2024; Machine Name: wallace-server

GNU bug tracking system

Debbugs is free software and licensed under the terms of the GNU Public License version 2. The current version can be obtained from https://bugs.debian.org/debbugs-source/.

Copyright © 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson, 2005-2017 Don Armstrong, and many other contributors.