Author Topic: can you force ssh/d to *only* use AES?  (Read 12617 times)

0 Members and 1 Guest are viewing this topic.

Offline DiTBhoTopic starter

  • Super Contributor
  • ***
  • Posts: 5098
  • Country: gb
Re: can you force ssh/d to *only* use AES?
« Reply #25 on: April 10, 2023, 06:07:47 am »
so, after testing ...

=dev-libs/openssl-3.0.8 supports "blowfish" via "legacy" engines, but it has a terrible bug detecting the dev-crypto hashing method and is not always recognized during sessions, which causes ssh connections to randomly close.

=dev-libs/openssl-1.0.2u compiles and works, but its Makefile doesn't respect "make install DESTDIR", the DESTDIR rule is not always respected, and this causes QA SandBox Access Violation ... so it fails on Catalyst

moral of the story, I am back with =dev-libs/openssl-1.1.1t-r3 :D

By switching from =dev-libs/openssl-3.0.* to =dev-libs/openssl-1.1.* you need to rebuild { sys-apps/coreutils, net-misc/wget, net-misc/curl, dev-libs/libevent } packages because they have a dependency with a specific version of =dev-libs/openssl-*

e.g.
Code: [Select]
# ldd /usr/bin/curl
        libssl.so.1.1 => /usr/lib/libssl.so.1.1 (0x77ac0000)
        libcrypto.so.1.1 => /usr/lib/libcrypto.so.1.1 (0x77860000)

libssl.so.1.0, libcrypto.so.1.0 ----> =dev-libs/openssl-1.0.*
libssl.so.1.1, libcrypto.so.1.1 ----> =dev-libs/openssl-1.1.*
libssl.so.3.1, libcrypto.so.3.0 ----> =dev-libs/openssl-3.0.*


p.s.
net-misc/openssh needs to be "hacked" in order to enable the "none" cipher since it's already supported by only for internal use.
Code: [Select]
# ssh -Q ciphers
aes128-cbc
aes192-cbc
aes256-cbc
aes128-ctr
aes192-ctr
aes256-ctr
none

now the stage4 is *exactly* as I want it to be  ;D
The opposite of courage is not cowardice, it is conformity. Even a dead fish can go with the flow
 


Share me

Digg  Facebook  SlashDot  Delicious  Technorati  Twitter  Google  Yahoo
Smf

 

-->