3 ms·
> That is a concern for the DH key establishment though, that might be decrypted in future. If you're paranoid, configure your SSH server to only accept Curve2
by ultramancool 10y ago
> That is a concern for the DH key establishment though, that might be decrypted in future.
If you're paranoid, configure your SSH server to only accept Curve25519-based key exchanges, only use AES with authenticated modes or CTR+ETM or chacha/poly1305, and only take ed25519 or long RSA authentication keys.
Assuming your clients are up to date it should work without any major impact. I also strongly recommend rejecting NIST "random" curves in your hostkey verification, better RSA or ed25519 than the current default of the somewhat questionable ECDSA-based keys.
- mkj 10y agoWon't the quantum computer break the curve25519 key exchange?
- Godel_unicode 10y agoYes. This advice is incorrect with regards to quantum computers.
- ultramancool 10y agoYes, eventually, but there's a lot bigger concerns than quantum computers currently.