-
-
Notifications
You must be signed in to change notification settings - Fork 13.2k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
openssh VerifyHostKeyDNS=yes can not verify sshfp-rr via dnssec #12470
Comments
|
I dug a bit into it and seems debian is patching its ssh with this patch: http://anonscm.debian.org/cgit/pkg-ssh/openssh.git/plain/debian/patches/dnssec-sshfp.patch Which seem to fix this issue. |
|
Setting |
|
Is this |
|
Sorry to mention this, it is an option of resolv.conf. |
|
The option |
|
So setting Maybe this could be made into an extra option like |
|
Hmm, have you found a reason not to enable |
|
I am not aware of any reason why |
|
DNSSEC is mainly interesting on resolver side. Resolvers should validate data (according to DNSSEC) even if the client doesn't express any interest in that. There are other advantages in client setting I'll test that locally for some time to check for larger problems. |
|
Pushed 11696e2. |
#12470 (comment) I've been using it for weeks without encountering any problems.
|
Uh oh. |
|
(I'm not sure how to understand that :) |
|
Perhaps this is what peti meant: #24433 breaks for me :) Perhaps this can still be the new default, but it should be probably documented properly since the risk of breaking against consumer routers. |
When I try to ssh into a box where I have configured some sshfp-rr with dnssec, I get get the prompt that the authenticity of the host could not be established. Here is a trimmed debug output:
When I dig the the corresponding sshfp record I get the
adflag, so they should be secure?:On a freebsd box with OpenSSH_6.6.1p1 and a debian box with OpenSSH_6.7p1 this feature works flawless: I can login without manual intervention.
The text was updated successfully, but these errors were encountered: