3 ms·
Yes: * https://man.openbsd.org/ssh_config.5#MACs https://man.openbsd.org/ssh_config.5#MACs * https://man.openbsd.org/sshd_config.5#MACs https://man.openbsd.or
by throw0101a 3mo ago
Yes:
* https://man.openbsd.org/ssh_config.5#MACs https://man.openbsd.org/ssh_config.5#MACs
* https://man.openbsd.org/sshd_config.5#MACs https://man.openbsd.org/sshd_config.5#MACs
ETM, encrypt-than-mac, variants are at the front of the preference list.
* https://en.wikipedia.org/wiki/UMAC_(cryptography) https://en.wikipedia.org/wiki/UMAC_(cryptography)
- lousken 3mo agoThat sucks, that means they will still appear in audits, they should remove them from the default.
- PunchyHamster 3mo agoOpenSSH thankfully cares little for corporate security theathre But I can sympathise, our stuff got flagged in audit because we foolishly assumed that some requirement was checked by just having OpenSSH "new enough",but it turned out that RedHat for that RHEL version patched back some old considered insecure primitives to keep their customers happy...
- deleted 3mo ago[deleted]