3 ms·
For the TLDR of this, I think the major point is the depreciation of ssh-rsa keys. They recommend switching to SHA2 with either ed25519 or the NIST P curves. Th
by invokestatic 6y ago
For the TLDR of this, I think the major point is the depreciation of ssh-rsa keys. They recommend switching to SHA2 with either ed25519 or the NIST P curves. They acknowledge the large amount of existing keys out there using RSA as a challenge.
- darkr 6y agoIncorrect. RSA keys are fine, the ssh-rsa key signature algorithm is not. You can instead use the rsa-sha2-256 signature algorithm with your RSA keys (and you will have been using this for some time if you are running non-ancient openssh).
- regecks 6y agoAs pointed out in other comments, it's not the case. It's deprecating an insecure way to use RSA keys to perform crypto operations. RSA keys themselves continue to be secure.