[Bug 933480] Re: Picks hmac-md5 over hmac-sha1

2012-02-18 Thread Clint Byrum
Hi Chris, thanks for taking the time to file this bug and help us make
Ubuntu better.

According to RFC 6151, this is not an urgent matter:

http://tools.ietf.org/html/rfc6151

I do think that it is rather odd that hmac-md5 is still the default, but
the upstream openssh authors seems to find that acceptable, and so I
think we can also follow their lead. This is perhaps something to take
up with the OpenSSH developers on their mailing list.

Because it is not urgent and upstream has not seen fit to correct the
issue, I am marking this bug as Wishlist. It is definitely something to
consider, so I'm marking it as Confirmed.

Chris, it would be fantastic if you would forward this bug to the
OpenSSH mailing list to get the ball rolling on on a discussion. Once
you've done so, report back here the results of the discussion, and we
can mark this as Triaged (if there is a change to make) or perhaps close
it if upstream is not interested in changing the default.

** Changed in: openssh (Ubuntu)
   Importance: Undecided = Wishlist

** Changed in: openssh (Ubuntu)
   Status: New = Confirmed

-- 
You received this bug notification because you are a member of Ubuntu
Server Team, which is subscribed to openssh in Ubuntu.
https://bugs.launchpad.net/bugs/933480

Title:
  Picks hmac-md5 over hmac-sha1

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/openssh/+bug/933480/+subscriptions

-- 
Ubuntu-server-bugs mailing list
Ubuntu-server-bugs@lists.ubuntu.com
Modify settings or unsubscribe at: 
https://lists.ubuntu.com/mailman/listinfo/ubuntu-server-bugs


[Bug 933480] Re: Picks hmac-md5 over hmac-sha1

2012-02-16 Thread Chris West
-- 
You received this bug notification because you are a member of Ubuntu
Server Team, which is subscribed to openssh in Ubuntu.
https://bugs.launchpad.net/bugs/933480

Title:
  Picks hmac-md5 over hmac-sha1

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/openssh/+bug/933480/+subscriptions

-- 
Ubuntu-server-bugs mailing list
Ubuntu-server-bugs@lists.ubuntu.com
Modify settings or unsubscribe at: 
https://lists.ubuntu.com/mailman/listinfo/ubuntu-server-bugs


[Bug 933480] Re: Picks hmac-md5 over hmac-sha1

2012-02-16 Thread Chris West
For precise, openssh-5.9 supports even more secure algorithms, so the line 
should perhaps be:
MACs 
hmac-sha2-512,hmac-sha2-256,hmac-sha1,hmac-ripemd160,umac...@openssh.com,hmac-md5,hmac-sha1-96,hmac-sha2-512-96,hmac-sha2-256-96,hmac-md5-96

-- 
You received this bug notification because you are a member of Ubuntu
Server Team, which is subscribed to openssh in Ubuntu.
https://bugs.launchpad.net/bugs/933480

Title:
  Picks hmac-md5 over hmac-sha1

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/openssh/+bug/933480/+subscriptions

-- 
Ubuntu-server-bugs mailing list
Ubuntu-server-bugs@lists.ubuntu.com
Modify settings or unsubscribe at: 
https://lists.ubuntu.com/mailman/listinfo/ubuntu-server-bugs