Skip to content

v3.9.4 — Require ECDSA host keys for SSH

Choose a tag to compare

@github-actions github-actions released this 14 Jul 08:08
· 183 commits to main since this release

SSH host keys must now be ecdsa-sha2-nistp256 — a single key that serves as both
the certificate subject and the ECIES recipient for encrypted KRL distribution (an
ed25519 signing key cannot do ECDH key agreement, so it can never receive an
encrypted KRL). Host registration and the fleet sign-host path reject non-P256
keys with an actionable message, and the register form now guides you to
/etc/ssh/ssh_host_ecdsa_key.pub — so a host can no longer be registered in a
state where it silently can't receive its revocation list.

Fix

  • ssh: require ecdsa-sha2-nistp256 host keys, fix register-form guidance

Full Changelog: v3.9.3...v3.9.4