Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <20080518161216.GZ12850@outflux.net>
Date: Sun, 18 May 2008 09:12:16 -0700
From: Kees Cook <kees@...flux.net>
To: oss-security@...ts.openwall.com
Subject: Re: OpenSSH key blacklisting

On Sun, May 18, 2008 at 04:06:55AM +0400, Solar Designer wrote:
> I've dropped the explicit CC because Kees is subscribed.

(I've adjusted my mail server to quit using SRS for the time being...)

> postings.  As to the fingerprint list, I'd appreciate it if you provide
> separate lists for different key types, sizes, and archs - such that we
> can produce any combinations.  The "unshortened" aspect is not as
> important; we'll probably pick last N bits of fingerprints anyway, to
> allow for comparison between our blacklist and that in the Debian and
> Ubuntu packages.

Ah, I haven't been separating it by arch, but I can certainly do that.
I've been including the "full" hashes in the Debian openssh-blacklist
source package and reducing them for the final files.  I can easily
split up the source blacklist files by arch and combine them during the
"build".

I will probably also keep the file in PID order, and sort it during the
build.  I've been interested in the pid origin just to see where in the
pid list keys tend to land.

-Kees

-- 
Kees Cook                                            @outflux.net

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.