On 4/29/15 12:29 AM, Mike Frysinger wrote:
> the latest openssh (6.8, not yet in our tree) makes openssl support
> optional. this is pretty nice:
> - smaller attack surface
> - smaller install size (drops 300k in openssh)
> - one fewer dep on openssl
>
> the trade off is backwards compatibility. w/out openssl, support for
> rsa/dsa/ecdsa is gone. only the new ed25519 keys are supported. these
> were first added to openssh-6.5 (our tree is out 6.6). it would mean
> our test keys would need updating, and anything relying on rsa keys
> explicitly.
>
Regarding the need to update the test keys: Isn't it more than
that? Specifically, won't this mean that any client that talks
to a device over ssh will need openssh-6.5 or later?
I checked the client systems I use most often; they're at 6.6.
However, I can imagine that there'll be users who aren't there
yet, and aren't prepared to upgrade.
I'll note that updating our test keys is itself a tricky business,
not to be undertaken lightly.
> what else can people think of in our system would be impacted ?
> -mike
>
> --
> --
> Chromium OS Developers mailing list:
chromiu...@chromium.org
> View archives, change email options, or unsubscribe:
>
http://groups.google.com/a/chromium.org/group/chromium-os-dev?hl=en
>
--
--jrb