-
Notifications
You must be signed in to change notification settings - Fork 1.8k
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
upstream: disable the DSA signature algorithm by default; ok
markus@ (yes, I know this expands to "the Digitial Signature Algorithm signature algorithm) OpenBSD-Commit-ID: 961ef594e46dd2dcade8dd5721fa565cee79ffed
- Loading branch information
Showing
8 changed files
with
46 additions
and
79 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -1,4 +1,4 @@ | ||
.\" $OpenBSD: ssh-add.1,v 1.86 2023/12/19 06:57:34 jmc Exp $ | ||
.\" $OpenBSD: ssh-add.1,v 1.87 2024/06/17 08:30:29 djm Exp $ | ||
.\" | ||
.\" Author: Tatu Ylonen <[email protected]> | ||
.\" Copyright (c) 1995 Tatu Ylonen <[email protected]>, Espoo, Finland | ||
|
@@ -35,7 +35,7 @@ | |
.\" (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF | ||
.\" THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. | ||
.\" | ||
.Dd $Mdocdate: December 19 2023 $ | ||
.Dd $Mdocdate: June 17 2024 $ | ||
.Dt SSH-ADD 1 | ||
.Os | ||
.Sh NAME | ||
|
@@ -67,10 +67,9 @@ When run without arguments, it adds the files | |
.Pa ~/.ssh/id_rsa , | ||
.Pa ~/.ssh/id_ecdsa , | ||
.Pa ~/.ssh/id_ecdsa_sk , | ||
.Pa ~/.ssh/id_ed25519 , | ||
.Pa ~/.ssh/id_ed25519_sk , | ||
.Pa ~/.ssh/id_ed25519 | ||
and | ||
.Pa ~/.ssh/id_dsa . | ||
.Pa ~/.ssh/id_ed25519_sk . | ||
After loading a private key, | ||
.Nm | ||
will try to load corresponding certificate information from the | ||
|
@@ -314,13 +313,12 @@ the built-in USB HID support. | |
.El | ||
.Sh FILES | ||
.Bl -tag -width Ds -compact | ||
.It Pa ~/.ssh/id_dsa | ||
.It Pa ~/.ssh/id_ecdsa | ||
.It Pa ~/.ssh/id_ecdsa_sk | ||
.It Pa ~/.ssh/id_ed25519 | ||
.It Pa ~/.ssh/id_ed25519_sk | ||
.It Pa ~/.ssh/id_rsa | ||
Contains the DSA, ECDSA, authenticator-hosted ECDSA, Ed25519, | ||
Contains the ECDSA, authenticator-hosted ECDSA, Ed25519, | ||
authenticator-hosted Ed25519 or RSA authentication identity of the user. | ||
.El | ||
.Pp | ||
|
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -1,4 +1,4 @@ | ||
.\" $OpenBSD: ssh-keygen.1,v 1.230 2023/09/04 10:29:58 job Exp $ | ||
.\" $OpenBSD: ssh-keygen.1,v 1.231 2024/06/17 08:30:29 djm Exp $ | ||
.\" | ||
.\" Author: Tatu Ylonen <[email protected]> | ||
.\" Copyright (c) 1995 Tatu Ylonen <[email protected]>, Espoo, Finland | ||
|
@@ -35,7 +35,7 @@ | |
.\" (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF | ||
.\" THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. | ||
.\" | ||
.Dd $Mdocdate: September 4 2023 $ | ||
.Dd $Mdocdate: June 17 2024 $ | ||
.Dt SSH-KEYGEN 1 | ||
.Os | ||
.Sh NAME | ||
|
@@ -51,7 +51,7 @@ | |
.Op Fl m Ar format | ||
.Op Fl N Ar new_passphrase | ||
.Op Fl O Ar option | ||
.Op Fl t Cm dsa | ecdsa | ecdsa-sk | ed25519 | ed25519-sk | rsa | ||
.Op Fl t Cm ecdsa | ecdsa-sk | ed25519 | ed25519-sk | rsa | ||
.Op Fl w Ar provider | ||
.Op Fl Z Ar cipher | ||
.Nm ssh-keygen | ||
|
@@ -205,7 +205,6 @@ section for details. | |
Normally each user wishing to use SSH | ||
with public key authentication runs this once to create the authentication | ||
key in | ||
.Pa ~/.ssh/id_dsa , | ||
.Pa ~/.ssh/id_ecdsa , | ||
.Pa ~/.ssh/id_ecdsa_sk , | ||
.Pa ~/.ssh/id_ed25519 , | ||
|
@@ -414,9 +413,8 @@ section. | |
Prints the contents of one or more certificates. | ||
.It Fl l | ||
Show fingerprint of specified public key file. | ||
For RSA and DSA keys | ||
.Nm | ||
tries to find the matching public key file and prints its fingerprint. | ||
will try to find the matching public key file and prints its fingerprint. | ||
If combined with | ||
.Fl v , | ||
a visual ASCII art representation of the key is supplied with the | ||
|
@@ -579,10 +577,9 @@ by key ID or serial number. | |
See the | ||
.Sx KEY REVOCATION LISTS | ||
section for details. | ||
.It Fl t Cm dsa | ecdsa | ecdsa-sk | ed25519 | ed25519-sk | rsa | ||
.It Fl t Cm ecdsa | ecdsa-sk | ed25519 | ed25519-sk | rsa | ||
Specifies the type of key to create. | ||
The possible values are | ||
.Dq dsa , | ||
.Dq ecdsa , | ||
.Dq ecdsa-sk , | ||
.Dq ed25519 , | ||
|
@@ -1290,13 +1287,12 @@ the built-in USB HID support. | |
.El | ||
.Sh FILES | ||
.Bl -tag -width Ds -compact | ||
.It Pa ~/.ssh/id_dsa | ||
.It Pa ~/.ssh/id_ecdsa | ||
.It Pa ~/.ssh/id_ecdsa_sk | ||
.It Pa ~/.ssh/id_ed25519 | ||
.It Pa ~/.ssh/id_ed25519_sk | ||
.It Pa ~/.ssh/id_rsa | ||
Contains the DSA, ECDSA, authenticator-hosted ECDSA, Ed25519, | ||
Contains the ECDSA, authenticator-hosted ECDSA, Ed25519, | ||
authenticator-hosted Ed25519 or RSA authentication identity of the user. | ||
This file should not be readable by anyone but the user. | ||
It is possible to | ||
|
@@ -1308,13 +1304,12 @@ but it is offered as the default file for the private key. | |
.Xr ssh 1 | ||
will read this file when a login attempt is made. | ||
.Pp | ||
.It Pa ~/.ssh/id_dsa.pub | ||
.It Pa ~/.ssh/id_ecdsa.pub | ||
.It Pa ~/.ssh/id_ecdsa_sk.pub | ||
.It Pa ~/.ssh/id_ed25519.pub | ||
.It Pa ~/.ssh/id_ed25519_sk.pub | ||
.It Pa ~/.ssh/id_rsa.pub | ||
Contains the DSA, ECDSA, authenticator-hosted ECDSA, Ed25519, | ||
Contains the ECDSA, authenticator-hosted ECDSA, Ed25519, | ||
authenticator-hosted Ed25519 or RSA public key for authentication. | ||
The contents of this file should be added to | ||
.Pa ~/.ssh/authorized_keys | ||
|
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -1,12 +1,12 @@ | ||
.\" $OpenBSD: ssh-keyscan.1,v 1.51 2024/06/14 05:20:34 jmc Exp $ | ||
.\" $OpenBSD: ssh-keyscan.1,v 1.52 2024/06/17 08:30:29 djm Exp $ | ||
.\" | ||
.\" Copyright 1995, 1996 by David Mazieres <[email protected]>. | ||
.\" | ||
.\" Modification and redistribution in source and binary forms is | ||
.\" permitted provided that due credit is given to the author and the | ||
.\" OpenBSD project by leaving this copyright notice intact. | ||
.\" | ||
.Dd $Mdocdate: June 14 2024 $ | ||
.Dd $Mdocdate: June 17 2024 $ | ||
.Dt SSH-KEYSCAN 1 | ||
.Os | ||
.Sh NAME | ||
|
@@ -130,22 +130,14 @@ The default is 5 seconds. | |
.It Fl t Ar type | ||
Specify the type of the key to fetch from the scanned hosts. | ||
The possible values are | ||
.Dq dsa , | ||
.Dq ecdsa , | ||
.Dq ed25519 , | ||
.Dq ecdsa-sk , | ||
.Dq ed25519-sk , | ||
or | ||
.Dq rsa . | ||
Multiple values may be specified by separating them with commas. | ||
The default is to fetch | ||
.Dq rsa , | ||
.Dq ecdsa , | ||
.Dq ed25519 , | ||
.Dq ecdsa-sk , | ||
and | ||
.Dq ed25519-sk | ||
keys. | ||
The default is to fetch all the above key types. | ||
.It Fl v | ||
Verbose mode: | ||
print debugging messages about progress. | ||
|
@@ -177,7 +169,7 @@ Find all hosts from the file | |
which have new or different keys from those in the sorted file | ||
.Pa ssh_known_hosts : | ||
.Bd -literal -offset indent | ||
$ ssh-keyscan -t rsa,dsa,ecdsa,ed25519 -f ssh_hosts | \e | ||
$ ssh-keyscan -t rsa,ecdsa,ed25519 -f ssh_hosts | \e | ||
sort -u - ssh_known_hosts | diff ssh_known_hosts - | ||
.Ed | ||
.Sh SEE ALSO | ||
|
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Oops, something went wrong.