3 ms·
Technically your keys are only used in the handshake. After that you'll get the same strength encryption regardless of the algo used for the original handshake
by kgo 16y ago
Technically your keys are only used in the handshake. After that you'll get the same strength encryption regardless of the algo used for the original handshake. So using DSA doesn't mean that your connections are now unencrypted.
The problem with DSA is that you can only have a key size of 1024 bits per the original standard. That's starting to get a little weak these days. (Keep that in mind if youi're using PuttyGen to make your keys!) This has since been changed, some systems use "dsa2" and higher bit counts, but it seems OpenSSH doesn't directly support that, at least according to the man page.
Anyway, the new version of OpenSSH just got ECC, which seems to be the future of public/private key encryption. So soon people will be talking trash on RSA. (I kid...)