Red Hat Bugzilla – Bug 1111568
AUTOCREATE_SERVER_KEYS=RSAONLY is not supported by init script
Last modified: 2018-04-17 13:13:33 EDT
Description of problem: openssh configuration file /etc/sysconfig/sshd says that it supports the f # AUTOCREATE_SERVER_KEYS=RSAONLY # AUTOCREATE_SERVER_KEYS=NO AUTOCREATE_SERVER_KEYS=YES But the init script /etc/init.d/sshd seems supports only YES and NO options, e.g. create all or none. Please note that this may cause troubles in FIPS, where DSA should be disallowed. Version-Release number of selected component (if applicable): openssh-5.3p1-94.el6 How reproducible: always Steps to Reproduce: # rm -f /etc/ssh/*key # grep ^AUTOCREATE_SERVER_KEYS /etc/sysconfig/sshd AUTOCREATE_SERVER_KEYS=YES # service sshd restart Stopping sshd: [ OK ] Generating SSH1 RSA host key: [ OK ] Generating SSH2 RSA host key: [ OK ] Generating SSH2 DSA host key: [ OK ] Starting sshd: [ OK ] # ll /etc/ssh/*key -rw-------. 1 root root 668 Jun 20 13:42 /etc/ssh/ssh_host_dsa_key -rw-------. 1 root root 963 Jun 20 13:42 /etc/ssh/ssh_host_key -rw-------. 1 root root 1675 Jun 20 13:42 /etc/ssh/ssh_host_rsa_key # # # # rm -f /etc/ssh/*key # vim /etc/sysconfig/sshd # grep ^AUTOCREATE_SERVER_KEYS /etc/sysconfig/sshd AUTOCREATE_SERVER_KEYS=RSAONLY # service sshd restart Stopping sshd: [ OK ] Generating SSH1 RSA host key: [ OK ] Generating SSH2 RSA host key: [ OK ] Generating SSH2 DSA host key: [ OK ] Starting sshd: [ OK ] # ll /etc/ssh/*key -rw-------. 1 root root 668 Jun 20 13:42 /etc/ssh/ssh_host_dsa_key -rw-------. 1 root root 963 Jun 20 13:42 /etc/ssh/ssh_host_key -rw-------. 1 root root 1675 Jun 20 13:42 /etc/ssh/ssh_host_rsa_key
A fix is quite simple and can be simply added to the update.
Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory, and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. http://rhn.redhat.com/errata/RHSA-2014-1552.html