4 ms·
Is hmac-sha1 and umac-64 still enabled by default?
by lousken 3mo ago
Is hmac-sha1 and umac-64 still enabled by default?
- throw0101a 3mo agoYes: * https://man.openbsd.org/ssh_config.5#MACs https://man.openbsd.org/ssh_config.5#MACs * https://man.openbsd.org/sshd_config.5#MACs https://man.openbsd.org/sshd_config.5#MACs ETM, encrypt-than-mac, variants are at the front of the preference list. * https://en.wikipedia.org/wiki/UMAC_(cryptography) https://en.wikipedia.org/wiki/UMAC_(cryptography)
- lousken 3mo agoThat sucks, that means they will still appear in audits, they should remove them from the default.
- PunchyHamster 3mo agoOpenSSH thankfully cares little for corporate security theathre But I can sympathise, our stuff got flagged in audit because we foolishly assumed that some requirement was checked by just having OpenSSH "new enough",but it turned out that RedHat for that RHEL version patched back some old considered insecure primitives to keep their customers happy...
- deleted 3mo ago[deleted]