CVSROOT: /cvs Module name: src Changes by: [email protected] 2014/03/31 21:34:10
Modified files:
usr.bin/ssh : sshconnect.c
Log message:
When using VerifyHostKeyDNS with a DNSSEC resolver, down-convert any
certificate keys to plain keys and attempt SSHFP resolution.
Prevents a server from skipping SSHFP lookup and forcing a new-hostkey
dialog by offering only certificate keys.
Reported by mcv21 AT cam.ac.uk
