Note: This bug is displayed in read-only format because the product is no longer active in Red Hat Bugzilla.
For bugs related to Red Hat Enterprise Linux 3 product line. The current stable release is 3.9. For Red Hat Enterprise Linux 6 and above, please visit Red Hat JIRA https://issues.redhat.com/secure/CreateIssue!default.jspa?pid=12332745 to report new issues.

Bug 186419

Summary: OpenSSH accepts ssh version 1 connections
Product: Red Hat Enterprise Linux 3 Reporter: Mark Komarinski <mkomarinski>
Component: opensshAssignee: Tomas Mraz <tmraz>
Status: CLOSED DEFERRED QA Contact: Brian Brock <bbrock>
Severity: medium Docs Contact:
Priority: medium    
Version: 3.0   
Target Milestone: ---   
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2006-03-23 15:28:43 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Mark Komarinski 2006-03-23 14:25:33 UTC
Description of problem:

SSH version 1 still allowed despite critical vulnerabilities of protocol

Version-Release number of selected component (if applicable):

All

How reproducible:

Every time

Steps to Reproduce:
1. Install base system
2. Check /etc/ssh/sshd_config
  
Actual results:

# Protocol 2,1

Expected results:

# Protocol 2
or 
Protocol 2

Additional info:

Please see http://www.ssh.com/company/newsroom/article/210/ and
http://www.kb.cert.org/vuls/id/684820

Comment 1 Tomas Mraz 2006-03-23 15:28:43 UTC
This problem will be resolved in a future major release of Red Hat Enterprise
Linux. Red Hat does not currently plan to provide a resolution for this in a Red
Hat Enterprise Linux update for currently deployed systems.

With the goal of minimizing risk of change for deployed systems, and in response
to customer and partner requirements, Red Hat takes a conservative approach when
evaluating changes for inclusion in maintenance updates for currently deployed
products. The primary objectives of update releases are to enable new hardware
platform support and to resolve critical defects.