[Touch-packages] [Bug 1898590] Re: Verify DNS fingerprints not working

2020-10-09 Thread Andreas Tauscher
The DNS queries captured with wireshark ssh to unbound and unbound to world looking correct and allways the AD flag in the responses is set. -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to openssh in Ubuntu. https://bugs.launc

[Touch-packages] [Bug 1898590] Re: Verify DNS fingerprints not working

2020-10-09 Thread Andreas Tauscher
With @localhost as parameter it will use the local resolver. Local resolver is unbound. The cr** systemd resolver is disabled. Configuration is exactly same like on another machine where it is working like expected. Only difference: Ubuntu 18.04 instead of 20.04. On 18.04 debug1: found 3 secure fi

[Touch-packages] [Bug 1898590] Re: Verify DNS fingerprints not working

2020-10-05 Thread Andreas Tauscher
ssh version is OpenSSH_8.2p1 Ubuntu-4ubuntu0.1, OpenSSL 1.1.1f 31 Mar 2020 -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to openssh in Ubuntu. https://bugs.launchpad.net/bugs/1898590 Title: Verify DNS fingerprints not worki

[Touch-packages] [Bug 1898590] [NEW] Verify DNS fingerprints not working

2020-10-05 Thread Andreas Tauscher
Public bug reported: When setting in /etc/ssh/ssh_config VerifyHostKeyDNS to yes the fingerprints are fetched, but the result is always: debug1: found n insecure fingerprints in DNS With dig +dnssec -tsshfp hostname the result is ok: ad flg is set. ** Affects: openssh (Ubuntu) Importance: U