Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

"Hardened Debian Server 12" policy requires updates #317

Open
perkelix opened this issue Jan 16, 2025 · 0 comments
Open

"Hardened Debian Server 12" policy requires updates #317

perkelix opened this issue Jan 16, 2025 · 0 comments

Comments

@perkelix
Copy link

perkelix commented Jan 16, 2025

new kex alias

Since 1:9.2p1-2+deb12u4 the OpenSSH port on Debian incldues the following:

Make sntrup761x25519-sha512 key exchange algorithm available without the @openssh.com suffix too.

This is to match what became available as an official kex since OpenSSH 9.9.

It would be a good idea to update the policy to avoid failing if the above backported feature is found.

Demote non-quantum to Optional

Likewise, this updated policy should consider curve25519-sha256* and diffie-hellman-* as Optional to match the recommendations of a scan performed without specifying the policy.

@perkelix perkelix changed the title new kex since OpenSSH 1:9.2p1-2+deb12u4 on Debian Bookworm new kex since OpenSSH 1:9.2p1-2+deb12u4 on Bookworm Jan 16, 2025
@perkelix perkelix changed the title new kex since OpenSSH 1:9.2p1-2+deb12u4 on Bookworm "Hardened Debian Server 12" policy requires updates Jan 17, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant