bugzilla-daemon at mindrot
Aug 31, 2012, 2:48 AM
Post #1 of 1
[Bug 2041] New: Check for SSHFP when certificate is offered.
Bug ID: 2041
Assignee: unassigned-bugs [at] mindrot
Summary: Check for SSHFP when certificate is offered.
Reporter: ondrej [at] caletka
Product: Portable OpenSSH
Created attachment 2185
Check for SSHFP when certificate is offered.
When the sshd offers a certificate to client (which is default, when
such a certificate is configured), the client refuses to do a SSHFP
validation for the key embedded in the certificate.
This patch fixes this by dropping certificate for the purpose of
checking SSHFP records, yet retaining certificate for other checks if
SSHFP authentication fails. It is therefore possible to fall back to
certificate authentication when for instance client does not have a
You are receiving this mail because:
You are watching the assignee of the bug.
openssh-bugs mailing list
openssh-bugs [at] mindrot