Bug 2088916
| Summary: | host-based authentication does not seem to work with rsa keys and gives an inscrutable error message | ||
|---|---|---|---|
| Product: | Red Hat Enterprise Linux 9 | Reporter: | Andrew Schorr <ajschorr> |
| Component: | openssh | Assignee: | Zoltan Fridrich <zfridric> |
| Status: | CLOSED ERRATA | QA Contact: | Marek Havrila <mhavrila> |
| Severity: | low | Docs Contact: | |
| Priority: | low | ||
| Version: | CentOS Stream | CC: | bstinson, jjelen, jwboyer, mhavrila, omoris, zfridric |
| Target Milestone: | rc | Keywords: | Reopened, Triaged |
| Target Release: | --- | ||
| Hardware: | Unspecified | ||
| OS: | Unspecified | ||
| Whiteboard: | |||
| Fixed In Version: | openssh-8.7p1-12.el9 | Doc Type: | No Doc Update |
| Doc Text: | Story Points: | --- | |
| Clone Of: | Environment: | ||
| Last Closed: | 2022-11-15 11:21:51 UTC | Type: | Bug |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
|
Description
Andrew Schorr
2022-05-21 15:03:55 UTC
Also, if ssh-rsa host key types are not supported, then why is the key generated by sshd-keygen.target? [root@localhost ssh]# cat /usr/lib/systemd/system/sshd-keygen.target [Unit] Wants=sshd-keygen Wants=sshd-keygen Wants=sshd-keygen PartOf=sshd.service Just remove "rsa" if it is no longer supported. RSA is still supported, but ssh-rsa signatures using SHA1 are no longer supported. What is the other system you are using? Does it support RFC 8332 [1]? Does it work with crypto policies set to legacy or DEFAULT:SHA1? [1] https://datatracker.ietf.org/doc/html/rfc8332 Looks like a duplicate of https://bugzilla.redhat.com/show_bug.cgi?id=2068423 to me *** This bug has been marked as a duplicate of bug 2068423 *** Reopening. Indeed, this is a different issue than the bug #2068423 as this involves ssh-keysign, which ignores SHA2 in OpenSSH 8.7p1 version. This should be fixed in upstream commit 7aa7b096cf2bafe2777085abdeed5ce00581f641 if I am right. Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory (openssh bug fix and enhancement update), and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://access.redhat.com/errata/RHBA-2022:8375 |