https://undeadly.org/cgi?action=article;sid=20210830113413 Front page [ ] [Search site] OpenBSD Journal Home Archives About Submit Story Create Account Login RSA/SHA1 signature type disabled by default in OpenSSH Contributed by rueda on 2021-08-30 from the Really Senile Algorthms dept. In a message to tech@ Damien Miller (djm@) explained the consequences of his recent commit: [...] RSA/SHA1, a.k.a the "ssh-rsa" signature type is now disabled by default in OpenSSH. While The SSH protocol confusingly uses overlapping names for key and signature algorithms, this does not stop the use of RSA keys and there is no need to regenerate "ssh-rsa" keys - most servers released in the last five years will automatically negotiate the use of RSA/SHA-256/512 signatures. This has been coming for a long time, but I do expect it will be distruptive for some people as there are likely to be some devices out there that cannot be upgraded to support the safer algorithms. In these cases, it is possible to selectively re-enable RSA/SHA1 support by specifying PubkeyAcceptedAlgorithms=+ssh-rsa in the ssh_config(5) or sshd_config(5) for the endpoint. Please report any problems here, to bugs@ or to openssh@ [...] TL;DR: * The "ssh-rsa" signature type is now disabled by default. * "ssh-rsa" signatures can be selectively re-enabled if necessary. * RSA ("ssh-rsa") keys are not affected by this change and remain valid. Reply --------------------------------------------------------------------- Latest Articles * Tue, Aug 31 + 10:29 Fair Internet bandwidth management on a network using OpenBSD (1) + 05:09 Hibernate time reduced (0) * Mon, Aug 30 + 11:34 RSA/SHA1 signature type disabled by default in OpenSSH (0) + 08:17 (open)rsync gains include/exclude support (1) * Thu, Aug 26 + 12:51 Recent and not so recent changes in OpenBSD that make life better (and may turn up elsewhere too) (0) * Thu, Aug 19 + 06:15 -current has moved to 7.0-beta (0) * Thu, Jul 22 + 07:23 Introducing dhcpleased(8) (7) * Sat, Jul 17 + 14:19 dhcpleased(8) and resolvd(8) enabled in base, replacing dhclient(8) (3) * Sat, Jun 19 + 16:16 Progress in support for the riscv64 platform (3) Credits Copyright (c) 2004-2008 Daniel Hartmeier. All rights reserved. Articles and comments are copyright their respective authors, submission implies license to publish on this web site. Contents of the archive prior to April 2nd 2004 as well as images and HTML templates were copied from the fabulous original deadly.org with Jose's and Jim's kind permission. This journal runs as CGI with httpd(8) on OpenBSD, the source code is BSD licensed. undeadly \Un*dead"ly\, a. Not subject to death; immortal. [Obs.]