[Bug 933480] Re: Picks hmac-md5 over hmac-sha1
Hi Chris, thanks for taking the time to file this bug and help us make Ubuntu better. According to RFC 6151, this is not an urgent matter: http://tools.ietf.org/html/rfc6151 I do think that it is rather odd that hmac-md5 is still the default, but the upstream openssh authors seems to find that acceptable, and so I think we can also follow their lead. This is perhaps something to take up with the OpenSSH developers on their mailing list. Because it is not urgent and upstream has not seen fit to correct the issue, I am marking this bug as Wishlist. It is definitely something to consider, so I'm marking it as Confirmed. Chris, it would be fantastic if you would forward this bug to the OpenSSH mailing list to get the ball rolling on on a discussion. Once you've done so, report back here the results of the discussion, and we can mark this as Triaged (if there is a change to make) or perhaps close it if upstream is not interested in changing the default. ** Changed in: openssh (Ubuntu) Importance: Undecided = Wishlist ** Changed in: openssh (Ubuntu) Status: New = Confirmed -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to openssh in Ubuntu. https://bugs.launchpad.net/bugs/933480 Title: Picks hmac-md5 over hmac-sha1 To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/openssh/+bug/933480/+subscriptions -- Ubuntu-server-bugs mailing list Ubuntu-server-bugs@lists.ubuntu.com Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-server-bugs
[Bug 933480] Re: Picks hmac-md5 over hmac-sha1
-- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to openssh in Ubuntu. https://bugs.launchpad.net/bugs/933480 Title: Picks hmac-md5 over hmac-sha1 To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/openssh/+bug/933480/+subscriptions -- Ubuntu-server-bugs mailing list Ubuntu-server-bugs@lists.ubuntu.com Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-server-bugs
[Bug 933480] Re: Picks hmac-md5 over hmac-sha1
For precise, openssh-5.9 supports even more secure algorithms, so the line should perhaps be: MACs hmac-sha2-512,hmac-sha2-256,hmac-sha1,hmac-ripemd160,umac...@openssh.com,hmac-md5,hmac-sha1-96,hmac-sha2-512-96,hmac-sha2-256-96,hmac-md5-96 -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to openssh in Ubuntu. https://bugs.launchpad.net/bugs/933480 Title: Picks hmac-md5 over hmac-sha1 To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/openssh/+bug/933480/+subscriptions -- Ubuntu-server-bugs mailing list Ubuntu-server-bugs@lists.ubuntu.com Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-server-bugs