Development issues regarding the cerowrt test router project
 help / color / mirror / Atom feed
* [Cerowrt-devel] Available MACs in dropbear
@ 2014-10-24 17:31 Maciej Soltysiak
  2014-10-24 17:52 ` Michael Richardson
  0 siblings, 1 reply; 7+ messages in thread
From: Maciej Soltysiak @ 2014-10-24 17:31 UTC (permalink / raw)
  To: cerowrt-devel

Hi list,

For some reason dropbear doesn't have modern MACs for SSH. On cero
3.10.36 I've got Dropbear SSH client v2013.59:

root@cerowrt:/etc# ssh -m help
ssh: Available MACs:
hmac-sha1-96,hmac-sha1,hmac-md5

(MD5 BTW...)
However, dropbear since v2013.56 has support for sha2
(https://matt.ucc.asn.au/dropbear/CHANGES):
Added hmac-sha2-256 and hmac-sha2-512 support (off by default, use options.h)

It might be that we don't have it enabled in the cero build.

The reason why it hurts me is that I have servers configured according
to bettercrypto.org and I can't connect from cero (rare occasions, but
they happen). I get:

ssh: Connection to user@server.com:22 exited: No matching algo mac c->s

I apologize for not looking at github, but I'm really low on time :-((

Do we have sha2 in dropbear in later cero versions or do we have to
modify the build?

I wonder what openwrt has configured...

Best regards,
Maciej

^ permalink raw reply	[flat|nested] 7+ messages in thread

end of thread, other threads:[~2014-10-25 15:37 UTC | newest]

Thread overview: 7+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2014-10-24 17:31 [Cerowrt-devel] Available MACs in dropbear Maciej Soltysiak
2014-10-24 17:52 ` Michael Richardson
2014-10-24 18:40   ` Maciej Soltysiak
2014-10-24 18:54     ` Michael Richardson
2014-10-25 12:31       ` Maciej Soltysiak
2014-10-25 13:36         ` Dave Taht
2014-10-25 15:37           ` Maciej Soltysiak

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox