]> git.ipfire.org Git - thirdparty/openssh-portable.git/commitdiff
upstream commit
authordjm@openbsd.org <djm@openbsd.org>
Fri, 3 Jul 2015 03:47:00 +0000 (03:47 +0000)
committerDamien Miller <djm@mindrot.org>
Wed, 15 Jul 2015 05:35:31 +0000 (15:35 +1000)
turn off 1024 bit diffie-hellman-group1-sha1 key
 exchange method (already off in server, this turns it off in the client by
 default too) ok dtucker@

Upstream-ID: f59b88f449210ab7acf7d9d88f20f1daee97a4fa

myproposal.h
ssh_config.5
sshd.c

index f0b9caa55c4dab5586fc07cc3f6431e317ee014e..371f27caefcf9b6a09db57bdbc5eaedb1ddac6df 100644 (file)
@@ -1,4 +1,4 @@
-/* $OpenBSD: myproposal.h,v 1.45 2015/07/03 03:43:18 djm Exp $ */
+/* $OpenBSD: myproposal.h,v 1.46 2015/07/03 03:47:00 djm Exp $ */
 
 /*
  * Copyright (c) 2000 Markus Friedl.  All rights reserved.
@@ -93,8 +93,7 @@
 
 #define KEX_CLIENT_KEX KEX_COMMON_KEX \
        "diffie-hellman-group-exchange-sha1," \
-       "diffie-hellman-group14-sha1," \
-       "diffie-hellman-group1-sha1"
+       "diffie-hellman-group14-sha1"
 
 #define        KEX_DEFAULT_PK_ALG      \
        HOSTKEY_ECDSA_CERT_METHODS \
index 268a627b2bc054fc5ff7baa6307a496241d1f5c9..d29963c15a427ded942fbe5aa8657f34f37f4616 100644 (file)
@@ -33,8 +33,8 @@
 .\" (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF
 .\" THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
 .\"
-.\" $OpenBSD: ssh_config.5,v 1.211 2015/06/02 09:10:40 djm Exp $
-.Dd $Mdocdate: June 2 2015 $
+.\" $OpenBSD: ssh_config.5,v 1.212 2015/07/03 03:47:00 djm Exp $
+.Dd $Mdocdate: July 3 2015 $
 .Dt SSH_CONFIG 5
 .Os
 .Sh NAME
@@ -980,8 +980,7 @@ curve25519-sha256@libssh.org,
 ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,
 diffie-hellman-group-exchange-sha256,
 diffie-hellman-group-exchange-sha1,
-diffie-hellman-group14-sha1,
-diffie-hellman-group1-sha1
+diffie-hellman-group14-sha1
 .Ed
 .Pp
 The list of available key exchange algorithms may also be obtained using the
diff --git a/sshd.c b/sshd.c
index 15af4e8e5944552d1762739feddc6bada68ffd78..801050013fe6ae1d2e95e6f496c528a62f955271 100644 (file)
--- a/sshd.c
+++ b/sshd.c
@@ -1,4 +1,4 @@
-/* $OpenBSD: sshd.c,v 1.451 2015/07/03 03:43:18 djm Exp $ */
+/* $OpenBSD: sshd.c,v 1.452 2015/07/03 03:47:00 djm Exp $ */
 /*
  * Author: Tatu Ylonen <ylo@cs.hut.fi>
  * Copyright (c) 1995 Tatu Ylonen <ylo@cs.hut.fi>, Espoo, Finland
@@ -2523,9 +2523,7 @@ sshd_hostkey_sign(Key *privkey, Key *pubkey, u_char **signature, size_t *slen,
        return 0;
 }
 
-/*
- * SSH2 key exchange: diffie-hellman-group1-sha1
- */
+/* SSH2 key exchange */
 static void
 do_ssh2_kex(void)
 {