BTS

Issue2158

Title openssh drops support for DSA, "failed: unknown or unsupported key type"
Priority bug Status resolved
Superseder Nosy List korn, mika
Assigned To mika Topics

Created on 2016-01-12.08:44:43 by korn, last changed 2016-01-12.10:00:52 by mika.

Messages
msg5815 (view) Author: mika Date: 2016-01-12.10:00:52
We believe that your issue has been closed by the upload of
Version 1.6.0 of grml-etc from Michael Prokop <mika@grml.org>.
The explanation is attached below

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Format: 1.8
Date: Tue, 12 Jan 2016 10:57:10 +0100
Source: grml-etc
Binary: grml-etc
Architecture: source all
Version: 1.6.0
Distribution: grml-testing
Urgency: medium
Maintainer: Michael Prokop <mika@grml.org>
Changed-By: Michael Prokop <mika@grml.org>
Description:
 grml-etc   - etcetera files for the Grml system
Changes:
 grml-etc (1.6.0) grml-testing; urgency=medium
 .
   * [697b566] No longer generate RSA1 SSH hostkey [Closes: issue2158]
     Thanks to Andras Korn for the bugreport
   * [1cb2de5] Bump Standards-Version to 3.9.6
Checksums-Sha1:
 98bfd989a38bf4d359e04bcc37f8ae0d89dd0b54 1524 grml-etc_1.6.0.dsc
 5f1065982e153ff92aee30a878dcb8dbc64b5650 93048 grml-etc_1.6.0.tar.xz
 daa5609de285483485a5772ca8c4f96ae09c3921 99510 grml-etc_1.6.0_all.deb
Checksums-Sha256:
 717ffebfeec8b7399345437daf4e8bfa5bb1751bc13e30f2babb017cd42ff79e 1524 grml-etc_1.6.0.dsc
 ec5b33c11034e066d1dd1aa5038206f6d71be494db6d880864053b42493755f6 93048 grml-etc_1.6.0.tar.xz
 55ff46c1236cbc5da29d45066b308d32bbb0c29e5024aa89cddff08d3023901b 99510 grml-etc_1.6.0_all.deb
Files:
 2e33a926daa99368b4c0be5280f4e9ac 1524 grml optional grml-etc_1.6.0.dsc
 6724df5e092a201c31d314e53d59f1dd 93048 grml optional grml-etc_1.6.0.tar.xz
 12284c9f672183f63068e6ecc64c7fb2 99510 grml optional grml-etc_1.6.0_all.deb

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIcBAEBCAAGBQJWlM5GAAoJEJaoeHK36jc3kdQP/2O9eo8JpQ5tmCqkkplCC5yF
GBxiU3EIBm3Ua3KrxKvylL3r/gefKaWg04JjX3kqeCKLTRkBF7mCLdzi84pvBVdI
b2yZ/W5g3J0D0+UtSCDC4SrWzjCfM2bbEN3E2/jNpP7Sd8l/hIclq7Ro+1OFXZ74
gSh+7vGXQtCSI2oFmJzuSecHgw61F+F4b/p53U0JsfV5L62GAdIJSI4f/jMn4lML
AlwK6XkSMxSk12+5DZ9Jb61f1eicOkJ6QRbWw5UKesjS5CfuJVthsimuYi8gPV/r
8clatA/2LHnulLWES7eR/r0ljBgX9vyLuqOuFXLSrBZtobBUbb1f6RrUlydCi7++
5W16vWMjapYRa7AH5i6IFtnmkmQgvv703yRyBghJ4M8ElTcxYw2eWMF8vSLbJ44w
h+PgRFy7guOxjdpTjLVkCY8uPf6a9RYCztkuZSdMUpFk2A40DBvC6PlR2xQdnDc+
ywRypAhBPsP7rFUjr38+9+DvF440ZSOqRsWxSZzBNCGnyDQabCA9J44mbcX7iD71
az8pJNyqB8tonHl9Arby/EFzSAWCUjOOr9cidoibYbaE8qacbr8rOq3FdyezJlLg
JZ/u7DJIbylgKXxESgy19Dp6Ve8QYq3dPUhVP2WQ7+6XJ9bvCvb7rY5LlWpfypLS
BTTcRVK/wWXyWXwfS6Fs
=LPpe
-----END PGP SIGNATURE-----
msg5814 (view) Author: mika Date: 2016-01-12.09:57:59
Actually it's the RSA1 type that's causing the problem, jftr.

Thanks Andras for the bugreport!
msg5813 (view) Author: korn Date: 2016-01-12.08:44:43
Recent daily sid images can't start sshd, probably because the config references
a DSA key and OpenSSH dropped support for DSA recently.

I would recommend to remove the HostKey /etc/ssh/host_dsa_key or similar line
from sshd_config unconditionally (also for grml versions not based on sid).
History
Date User Action Args
2016-01-12 10:00:52mikasetstatus: fixed-in-git -> resolved
nosy: mika, korn
messages: + msg5815
2016-01-12 09:57:59mikasetstatus: unread -> fixed-in-git
assignedto: mika
messages: + msg5814
nosy: + mika
2016-01-12 08:44:43korncreate