public inbox for [email protected]  
help / color / mirror / Atom feed
From: Dave Page <[email protected]>
To: Akshay Joshi <[email protected]>
Cc: Sven <[email protected]>
Cc: pgAdmin Support <[email protected]>
Subject: Re: SSH tunnel key exchange methods
Date: Mon, 30 Nov 2015 13:08:38 +0000
Message-ID: <[email protected]> (raw)
In-Reply-To: <CANxoLDfRohWSnXsFxBv+bPFugUaDPBYXpTeQDcbPQy7j=_cW2g@mail.gmail.com>
References: <[email protected]>
	<CA+OCxozWb1AMK_mOOZo_QF1w5i=4bx=MoO=Q2UavPihZ54aWJA@mail.gmail.com>
	<CANxoLDdJT6KXXTZ860DdopC8Txb6Pd2yX3NvZudb_HhwYxrU+w@mail.gmail.com>
	<CANxoLDfRohWSnXsFxBv+bPFugUaDPBYXpTeQDcbPQy7j=_cW2g@mail.gmail.com>
List-Unsubscribe:  <mailto:[email protected]?body=unsub%20pgadmin-support>

Ok, thanks Akshay.

-- 
Dave Page
Blog: http://pgsnake.blogspot.com
Twitter: @pgsnake

EnterpriseDB UK:http://www.enterprisedb.com
The Enterprise PostgreSQL Company

> On 30 Nov 2015, at 12:57, Akshay Joshi <[email protected]> wrote:
> 
> Hi Dave
> 
>> On Mon, Nov 30, 2015 at 10:41 AM, Akshay Joshi <[email protected]> wrote:
>> Hi Dave
>> 
>>> On Fri, Nov 27, 2015 at 3:01 PM, Dave Page <[email protected]> wrote:
>>> On Fri, Nov 27, 2015 at 9:23 AM, Sven <[email protected]> wrote:
>>> >> The key exchange methods offered when opening an SSH tunnel are all
>>> >> SHA1 and therefore too weak:
>>> >>
>>> >> [sshd] fatal: Unable to negotiate with xxx.xxx.xxx.xxx: no matching
>>> >> key exchange method found. Their offer:
>>> >> diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1,
>>> >> diffie-hellman-group1-sha1 [preauth]
>>> >
>>> > Any news on this? If there's no easy way to add safer kexes, I suggest
>>> > you disable the SSH feature altogether. SHA1 is dead and IMO nobody
>>> > should trust a connection established with SHA1 kexes in order to talk
>>> > to databases.
>>> 
>>> Akshay, you know that code best of all. How do we enable safer kexes?
>> 
>>    Today I'll look into it on priority and update accordingly.
>  
>        I have found that "diffie-hellman-group-exchange-sha256" support has been added to the libssh2 code on September 24, it's not released yet. Please check https://github.com/libssh2/libssh2/pull/48 . Today I have tried to update the libssh2, but facing some compilation issues which needs to be fixed. I am working on it and then check do we need to change our logic or libssh2 will automatically used  "diffie-hellman-group-exchange-sha256".
>  
>>> 
>>> --
>>> Dave Page
>>> Blog: http://pgsnake.blogspot.com
>>> Twitter: @pgsnake
>>> 
>>> EnterpriseDB UK: http://www.enterprisedb.com
>>> The Enterprise PostgreSQL Company
>> 
>> 
>> 
>> -- 
>> Akshay Joshi
>> Principal Software Engineer 
>> 
>> 
>> 
>> Phone: +91 20-3058-9517
>> Mobile: +91 976-788-8246
> 
> 
> 
> -- 
> Akshay Joshi
> Principal Software Engineer 
> 
> 
> 
> Phone: +91 20-3058-9517
> Mobile: +91 976-788-8246


view thread (17+ messages)  latest in thread

reply

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Reply to all the recipients using the --to and --cc options:
  reply via email

  To: [email protected]
  Cc: [email protected], [email protected], [email protected], [email protected]
  Subject: Re: SSH tunnel key exchange methods
  In-Reply-To: <[email protected]>

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

This inbox is served by agora; see mirroring instructions
for how to clone and mirror all data and code used for this inbox