OpenSSH v7.6 Released
openssh.com
openssh.com
Is there anyone inconvenienced by this?
https://blog.famzah.net/2015/06/26/openssh-ciphers-performan...
Technically, yeah, I was inconvenienced but, meh, not really. It took all of three minutes to troubleshoot and fix and it was entirely my fault for not reading the changelog before upgrading first. Again, this was just a laptop and this would not have affected anything in production (I'm not sure if any other distros stay that up-to-date).
That situation will likely repeat itself with this latest upgrade.
Not that I don't support their decision to drop support for these deprecated algorithms, it's our fault for running outdated software.
Actually the only thing that annoys me in these release notes is:
>Please note that the SHA256 signatures are base64 encoded and not hexadecimal (which is the default for most checksum tools).
Then why not use hex? Neither GNU coreutil's sha256sum nor FreeBSD's sha256 supports outputting in base64. OpenBSD's sha256 has a '-b' switch for base64 but by default it's in hex as well. Is it really worth adding this pain on the user just to save 20 bytes?
I update my sshd configs untill they're green [0] and love to see the bots fail with even establishing a connection. You can even distinguish the different bot families by their (limited) protocols.
There should be a service similar to Mozilla's TLS configuration generator[1], but for SSH.
Mozilla does have a wiki page with modern and intermediate SSH configurations[2], but I'm not sure whether the advice is still current, and a configuration generator page would probably be more accessible. I wonder if they would be open to creating one.
[1] https://mozilla.github.io/server-side-tls/ssl-config-generat...
As to the up to dateness of the Mozilla Guidelines: it is not. Just see the entry "UsePrivilegeSeparation sandbox" which has been deprecated since 7.5 [0]