Skip to content

Conversation

@alex
Copy link
Member

@alex alex commented Feb 12, 2016

These are being removed from OpenSSH as well: openssh/openssh-portable@714e367

@alex
Copy link
Member Author

alex commented Feb 12, 2016

Failing test appears to be a known one.

@coveralls
Copy link

Coverage Status

Coverage decreased (-0.03%) to 72.555% when pulling ec0da66 on alex:patch-1 into a14d266 on paramiko:master.

@bitprophet bitprophet added this to the 3.0 milestone Apr 25, 2016
@bitprophet
Copy link
Member

Dropping this in 3.0 mostly because I've been telling folks 2.0 will remain API/behavior compatible. As noted elsewhere 3.0 will still go out in the nearish future :) thanks!

@coveralls
Copy link

Coverage Status

Coverage remained the same at 72.41% when pulling 273a1e1 on alex:patch-1 into 8664514 on paramiko:master.

openstack-mirroring pushed a commit to openstack/networking-generic-switch that referenced this pull request Mar 5, 2025
In order for n-g-s to be able to run on a node in FIPS enforcing mode,
it *must* not use md5. However, paramiko's code has a get_fingerprint
call where it is fingerprinting data for the exchange to identify
a difference, which can use any algorithm realistically.

Anyhow, this is necessary because it appears that paramiko's maintainer
is not really interested in fixing the md5 usage. As a result, we're
forced to monkeypatch paramiko, which is loaded by netmiko, which is
what NGS uses.

This should be fixed in paramiko, but also it seems several changes
been proposed without forward movement.

https: //github.com/paramiko/paramiko/pull/688
https: //github.com/paramiko/paramiko/pull/1103
https: //github.com/paramiko/paramiko/pull/2189
https: //github.com/paramiko/paramiko/pull/2496
https: //github.com/paramiko/paramiko/issues/2383
https: //github.com/paramiko/paramiko/issues/396
Related-Bug: 2098819
Change-Id: Ia3fb9d2baa14be1726197d1115e92adc9ce5ce0a
openstack-mirroring pushed a commit to openstack/openstack that referenced this pull request Mar 5, 2025
* Update networking-generic-switch from branch 'master'
  to b351b9136d569b02c8b94df3e52fdd10038df3c4
  - Merge "don't use paramiko's get_fingerprint (md5)"
  - don't use paramiko's get_fingerprint (md5)
    
    In order for n-g-s to be able to run on a node in FIPS enforcing mode,
    it *must* not use md5. However, paramiko's code has a get_fingerprint
    call where it is fingerprinting data for the exchange to identify
    a difference, which can use any algorithm realistically.
    
    Anyhow, this is necessary because it appears that paramiko's maintainer
    is not really interested in fixing the md5 usage. As a result, we're
    forced to monkeypatch paramiko, which is loaded by netmiko, which is
    what NGS uses.
    
    This should be fixed in paramiko, but also it seems several changes
    been proposed without forward movement.
    
    https: //github.com/paramiko/paramiko/pull/688
    https: //github.com/paramiko/paramiko/pull/1103
    https: //github.com/paramiko/paramiko/pull/2189
    https: //github.com/paramiko/paramiko/pull/2496
    https: //github.com/paramiko/paramiko/issues/2383
    https: //github.com/paramiko/paramiko/issues/396
    Related-Bug: 2098819
    Change-Id: Ia3fb9d2baa14be1726197d1115e92adc9ce5ce0a
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants