Red Hat Bugzilla – Bug 187211
RFE: Include GSSAPI Key Exchange support in OpenSSH RPM
Last modified: 2009-04-28 04:02:06 EDT
The GSSAPI support in the distributed OpenSSH supports user authentication only.
This means that site administrators are still required to maintain ssh known hosts
lists, which is a significant chore for large sites. GSSAPI key exchange allows
the use of Kerberos to authenticate the server to the client, and so removes the
need for known hosts files.
Many other vendors already distribute OpenSSH (or their own SSH client) with
GSSAPI key exchange support - amongst those doing so are Debian, Apple and Sun.
Patches to implement GSSAPI key exchange are available from this bugs URL, and
have been in widespread use for a number of years.
It would be great to get this support into Fedora / RHEL, to avoid everyone
having to build their own OpenSSH RPMS. The I-D documenting both key exchange
and userauth is in the RFC editor queue, making further changes to the protocol
This is interesting enhancement request however we generally prefer keeping our
packages as close to upstream as possible. Was this patch submitted upstream to
the openssh development mailing lists or bugzilla.mindrot.org? If yes what was
the upstream developers' reaction?
It was pushed upstream at the same time as the GSSAPI user authentication code.
After a considerable amount of discussion, the OpenSSH folks elected to take only
the user authentication code.
Upstream were concerned about the complexity of the entire GSSAPI patch drop. A
number of things got cut in order to simplify the code to meet their requirements
(decent error reporting, for one) Unfortunately, they also couldn't be convinced
of key exchange's benefits for those sites running Kerberos infrastructures.
Well if they were concerned about the complexity of the entire GSSAPI patch
maybe they could accept the key exchange patch now that the client
authentication part of the patch is already there for a long time.
Could you try to resubmit the patch to bugzilla.mindrot.org so it can be
I have also one question - how can I disable the key exchange on the client side
so the server is verified by the normal public key method?
I have a patch which I'll be submitting following the forthcoming
The new GSSAPI key-exchange patch includes support for the
'GSSAPIKeyExchange' option on the client, as well as the server,
which should solve your second issue.
I'll leave updating the 'I am providing the requested information'
box until I have a bugzilla.mindrot.org bug to reference here.
I've added the patch to bugzilla.mindrot.org. In the hope of making it acceptable to them, its a minimalist
version of the patch I distribute from my website, without the other features that patch includes, which I'm
breaking out into individual bugs, on bugzilla.mindrot.org
Can I Second this request? It makes total sense for large sites.
If you want to lobby somewhere for this feature, please do that in the upstream
This package has changed ownership in the Fedora Package Database. Reassigning to the new owner of this component.
If this is again being considered can the "Cascading Credentials" part of the "Key Exchange" patch be considered at the same time.
Both look right the correct thing to do particularly in a IPA environment.
We believe that it is more appropriate for this issue to be resolved upstream.
Red Hat will continue to track the issue in the centralized upstream bug tracker, and will review any bug fixes that become available for consideration in future updates.
Thank you for the bug report.