CVSROOT: /cvs Module name: src Changes by: d...@cvs.openbsd.org 2014/03/31 21:34:10
Modified files: usr.bin/ssh : sshconnect.c Log message: When using VerifyHostKeyDNS with a DNSSEC resolver, down-convert any certificate keys to plain keys and attempt SSHFP resolution. Prevents a server from skipping SSHFP lookup and forcing a new-hostkey dialog by offering only certificate keys. Reported by mcv21 AT cam.ac.uk