PHWinfo banniere

ACCUEIL ANNUAIRE ARTICLES COMPARATIF HÉBERGEURS DEVIS FORUMS RÉDUCTEUR D'URL
Go Back   PHWinfo > Forums Hébergement > Forum Serveur - Sécurité et techniques > comp.security.ssh > Interesting changes in OpenSSH 5.4p1 that affected Putty
FAQ Members List Search Today's Posts Mark Forums Read
comp.security.ssh SSH secure remote login and tunneling tools.

Interesting changes in OpenSSH 5.4p1 that affected Putty

Reply
 
Thread Tools
Old 04/08/10, 04:36   #1
Man-wai Chang to The Door (33600bps)
Aucun Avatar
 
Posts: n/a
Hébergeur:
Default Interesting changes in OpenSSH 5.4p1 that affected Putty


From its change log: http://www.openssh.com/txt/release-5.4

* New RSA keys will be generated with a public exponent of RSA_F4 ==
(2**16)+1 == 65537 instead of the previous value 35.

* Passphrase-protected SSH protocol 2 private keys are now protected
with AES-128 instead of 3DES. This applied to newly-generated keys
as well as keys that are reencrypted (e.g. by changing their
passphrase).

Puttygen could NOT handle the new passphrase-protected key.

--
@~@ Might, Courage, Vision, SINCERITY.
/ v \ Simplicity is Beauty! May the Force and Farce be with you!
/( _ )\ (x86_64 Ubuntu 9.10) Linux 2.6.33.2
^ ^ 11:36:01 up 4 days 3:28 2 users load average: 0.00 0.00 0.00
ä¸å€Ÿè²¸! ä¸è©é¨™! 䏿´äº¤! 䏿‰“交! 䏿‰“劫! ä¸è‡ªæ®º! è«‹è€ƒæ…®ç¶œæ´ (CSSA):
http://www.swd.gov.hk/tc/index/site_...sub_addressesa
  Reply With Quote
Old 04/11/10, 11:36   #2
Man-wai Chang to The Door (33600bps)
Aucun Avatar
 
Posts: n/a
Hébergeur:
Default Re: Interesting changes in OpenSSH 5.4p1 that affected Putty


Error message from puttygen.exe:

Couldn't load private key (ciphers other than DES-EDE3-CBC not supported

On 4/8/2010 11:36, Man-wai Chang to The Door (33600bps) wrote:
>
> From its change log: http://www.openssh.com/txt/release-5.4
>
> * New RSA keys will be generated with a public exponent of RSA_F4 ==
> (2**16)+1 == 65537 instead of the previous value 35.
>
> * Passphrase-protected SSH protocol 2 private keys are now protected
> with AES-128 instead of 3DES. This applied to newly-generated keys
> as well as keys that are reencrypted (e.g. by changing their
> passphrase).



--
@~@ Might, Courage, Vision, SINCERITY.
/ v \ Simplicity is Beauty! May the Force and Farce be with you!
/( _ )\ (x86_64 Ubuntu 9.10) Linux 2.6.33.2
^ ^ 18:36:01 up 7 days 10:28 2 users load average: 3.58 4.22 3.82
ä¸å€Ÿè²¸! ä¸è©é¨™! 䏿´äº¤! 䏿‰“交! 䏿‰“劫! ä¸è‡ªæ®º! è«‹è€ƒæ…®ç¶œæ´ (CSSA):
http://www.swd.gov.hk/tc/index/site_...sub_addressesa
  Reply With Quote
Old 04/15/10, 23:17   #3
Jacob Nevins
Aucun Avatar
 
Posts: n/a
Hébergeur:
Default Re: Interesting changes in OpenSSH 5.4p1 that affected Putty

Man-wai Chang to The Door (33600bps) <toylet.toylet@gmail.com> writes:
> From its change log: http://www.openssh.com/txt/release-5.4
>
>* New RSA keys will be generated with a public exponent of RSA_F4 ==
> (2**16)+1 == 65537 instead of the previous value 35.
>
>* Passphrase-protected SSH protocol 2 private keys are now protected
> with AES-128 instead of 3DES. This applied to newly-generated keys
> as well as keys that are reencrypted (e.g. by changing their
> passphrase).
>
>Puttygen could NOT handle the new passphrase-protected key.


Support for AES encryption has been added to the development snapshots
of PuTTYgen (from r8916, 2010-04-13). Windows executables built
nightly are available from the PuTTY website to try.

(I don't think the exponent change will affect PuTTYgen?)
  Reply With Quote
Old 04/16/10, 12:10   #4
Man-wai Chang to The Door (33600bps)
Aucun Avatar
 
Posts: n/a
Hébergeur:
Default Re: Interesting changes in OpenSSH 5.4p1 that affected Putty

>> * Passphrase-protected SSH protocol 2 private keys are now protected
>> with AES-128 instead of 3DES. This applied to newly-generated keys
>> as well as keys that are reencrypted (e.g. by changing their
>> passphrase).
>>
>> Puttygen could NOT handle the new passphrase-protected key.

>
> Support for AES encryption has been added to the development snapshots
> of PuTTYgen (from r8916, 2010-04-13). Windows executables built
> nightly are available from the PuTTY website to try.
>
> (I don't think the exponent change will affect PuTTYgen?)


Excellent! Thank you again!

--
@~@ Might, Courage, Vision, SINCERITY.
/ v \ Simplicity is Beauty! May the Force and Farce be with you!
/( _ )\ (x86_64 Ubuntu 9.10) Linux 2.6.33.2
^ ^ 19:10:01 up 12 days 11:02 2 users load average: 1.01 1.05 1.09
ä¸å€Ÿè²¸! ä¸è©é¨™! 䏿´äº¤! 䏿‰“交! 䏿‰“劫! ä¸è‡ªæ®º! è«‹è€ƒæ…®ç¶œæ´ (CSSA):
http://www.swd.gov.hk/tc/index/site_...sub_addressesa
  Reply With Quote
Reply


Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off


All times are GMT +1. The time now is 09:25.


Powered by vBulletin® ©2000 - 2012, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.3.0
PHWinfo is a website Education Without Frontiers
Ad Management by RedTyger
All rights reserved
Page generated in 0.14756 seconds with 7 queries