You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Since 1:9.2p1-2+deb12u4 the OpenSSH port on Debian incldues the following:
Make sntrup761x25519-sha512 key exchange algorithm available without the @openssh.com suffix too.
This is to match what became available as an official kex since OpenSSH 9.9.
It would be a good idea to update the policy to avoid failing if the above backported feature is found.
Demote non-quantum to Optional
Likewise, this updated policy should consider curve25519-sha256* and diffie-hellman-* as Optional to match the recommendations of a scan performed without specifying the policy.
The text was updated successfully, but these errors were encountered:
perkelix
changed the title
new kex since OpenSSH 1:9.2p1-2+deb12u4 on Debian Bookworm
new kex since OpenSSH 1:9.2p1-2+deb12u4 on Bookworm
Jan 16, 2025
perkelix
changed the title
new kex since OpenSSH 1:9.2p1-2+deb12u4 on Bookworm
"Hardened Debian Server 12" policy requires updates
Jan 17, 2025
new kex alias
Since 1:9.2p1-2+deb12u4 the OpenSSH port on Debian incldues the following:
Make sntrup761x25519-sha512 key exchange algorithm available without the @openssh.com suffix too.
This is to match what became available as an official kex since OpenSSH 9.9.
It would be a good idea to update the policy to avoid failing if the above backported feature is found.
Demote non-quantum to Optional
Likewise, this updated policy should consider
curve25519-sha256*
anddiffie-hellman-*
as Optional to match the recommendations of a scan performed without specifying the policy.The text was updated successfully, but these errors were encountered: