3 ms·
Does SSHv3 implementation exists as an Open Source Server/Client version?
by based2 5y ago
Does SSHv3 implementation exists as an Open Source Server/Client version?
- tw04 5y agoThere isn’t even a draft specification for SSHv3 so anyone claiming to have a server/client implementation (closed source or otherwise) is playing fast and loose with the term to try to sell something. https://datatracker.ietf.org/wg/secsh/about/ https://datatracker.ietf.org/wg/secsh/about/
- based2 5y agohttps://media.defense.gov/2020/Aug/18/2002479461/-1/-1/0/HARDENING_NETWORK_DEVICES.PDF https://media.defense.gov/2020/Aug/18/2002479461/-1/-1/0/HAR...
- frutiger 5y agoThere is indeed no such thing as SSH3. I’m somewhat certain that document is supposed to say “SSLv3 or TLS”. It’s a minor typo but it brings into question the validity of the rest of the document.
- tialaramex 5y agoSSLv3 seems unlikely in 2020 document about security. TLS 1.0 and TLS 1.1 are already known to be a bad idea by then, and SSLv3 was formally deprecated in 2015. Whereas a typo of SSHv2 makes sense because you probably do want SSHv2 on products which have it, even if they also speak TLS 1.2 or better, since the functionality is orthogonal.
- jhgb 5y agoBut the "Use SSH or TLS" interpretation seems to make as much sense as saying "use a square or a yellow" regarding shapes. SSH is not (easily, anyway) a substitute for TLS where TLS is applicable.
- stonogo 5y agoThey both provide line encryption to underlying applications. In the early days of ssh the main competitor was rsh over an ssl tunnel.
- tialaramex 5y agoThis document isn't suggesting which services to use it's telling you what should be enabled, it's titled "Hardening Network Devices" and says "Research should be done to determine what services are running by default. The following guidance will serve to determine the services that should be enabled or disabled" Among the services they recommend disabling are: Daytime, BootP, and telnet.
- tialaramex 5y agoHuman types "3" when they meant "2" versus shadowy US government agency has invented a completely new cryptographic protocol that everybody needs to use yet somehow escaped mention anywhere except this one document... Who knows right? It is amusing reading the confused warblings of people who've been handed a mandate for something that doesn't exist. "How do I enable SSHv3 on this Cisco router?". We don't have many pranks in our industry, perhaps enabling SSHv3 can be our left-handed screwdriver or gallon of prop wash.