3 ms·
Keep in mind that many of the preferred key exchange algorithms and ciphers have changed vastly since 2006. OpenSSH has been improving in the cryptography depa
by shittyadmin 8y ago
Keep in mind that many of the preferred key exchange algorithms and ciphers have changed vastly since 2006.
OpenSSH has been improving in the cryptography department by leaps and bounds.
OpenSSH 5.2 switched to preferring AES-CTR.
OpenSSH 5.7 added ECDH as a kex and ECDSA as for signing.
OpenSSH 6.2 added encrypt-then-mac and prefers it by default.
OpenSSH 6.5 added Curve25519 as a kex and chacha20-poly1305 as a cipher. As well as Ed25519 for signing.
OpenSSH 8 will add quantum resistant algorithms for key exchange.
- HocusLocus 8y agogreatadmin, thanks!
- nullc 8y ago> OpenSSH 8 will add quantum resistant algorithms for key exchange. Any additional information? This is really good to hear. PQ key exchange in SSH makes a lot of sense: Except when its used as some backend communications for automation SSH key establishment is hardly performance critical, and can easily afford extra round trips for negotiation. Any idea if there are plans for PQ key authentication? A SPHINCS signature or similar would be very nice-- and the security story for hash based signatures is excellent.
- jakobdabo 8y ago> Any additional information? https://lists.mindrot.org/pipermail/openssh-unix-dev/2019-March/037672.html https://lists.mindrot.org/pipermail/openssh-unix-dev/2019-Ma... https://codesmithdev.com/openssh-8-0-releasing-with-quantum-computing-resistant-keys/ https://codesmithdev.com/openssh-8-0-releasing-with-quantum-...
- shittyadmin 8y agoThey're using a mixture of Streamlined NTRU Prime 4591^761 and X25519. https://ntruprime.cr.yp.to/ https://ntruprime.cr.yp.to/ Note that this is still considered "experimental" and probably won't be enabled by default. I'd advise checking out some of the recent DJB and Tanja Lange talks for further detail on how research on these algorithms is progressing: https://www.youtube.com/watch?v=ZCmnQR3_qWg https://www.youtube.com/watch?v=ZCmnQR3_qWg There's also the older but still relevant PQCHacks: https://media.ccc.de/v/32c3-7210-pqchacks https://media.ccc.de/v/32c3-7210-pqchacks Haven't seen any talk of post quantum signatures in changelogs yet at least, but research is happening rapidly in this field and OpenSSH has really upped their game in recent years.