Re: Accepted openssh-blacklist 0.3 (source all)

2008-05-21 Thread Kees Cook
On Wed, May 21, 2008 at 07:07:34AM +0200, Vincent Bernat wrote: OoO En cette nuit nuageuse du mercredi 21 mai 2008, vers 01:32, Kees Cook [EMAIL PROTECTED] disait: * Add empty DSA-2048, since they weren't any bad ones. How is it possible? I could be mistaken, but prior to openssl

Re: Accepted openssh-blacklist 0.3 (source all)

2008-05-21 Thread Simon Valiquette
Kees Cook un jour écrivit: On Wed, May 21, 2008 at 07:07:34AM +0200, Vincent Bernat wrote: I could be mistaken, but prior to openssl breaking, ssh-keygen stopped allowing dsa 2048 keys, which means there wasn't a way to generate bad ones: It didn't before. At least not directly from

Re: Accepted openssh-blacklist 0.3 (source all)

2008-05-21 Thread Kees Cook
Hi, On Wed, May 21, 2008 at 05:42:43AM -0400, Simon Valiquette wrote: Kees Cook un jour écrivit: On Wed, May 21, 2008 at 07:07:34AM +0200, Vincent Bernat wrote: I could be mistaken, but prior to openssl breaking, ssh-keygen stopped allowing dsa 2048 keys, which means there wasn't a way to

Re: Accepted openssh-blacklist 0.3 (source all)

2008-05-20 Thread Vincent Bernat
OoO En cette nuit nuageuse du mercredi 21 mai 2008, vers 01:32, Kees Cook [EMAIL PROTECTED] disait: * Add empty DSA-2048, since they weren't any bad ones. How is it possible? Thanks. -- BOFH excuse #63: not properly grounded, please bury computer pgp3twM6bO48f.pgp Description: PGP