[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: SecurityPortal re: Attacks on SSH and SSL



 
> OpenSSH will print a note telling you that the key on the other end
> has been changed. It will warn about a possible man in the middle
> attack. It will force you to remove the old key before you will be able
> to connect the the remote host. If you read all the text and then removes
> the old key without checking with the other end you are stupid.

 On a related note, is it possible (or does it actually make sense) to
 generate a fingerprint for a DSA host key?
 
$ ssh-keygen -l -f /etc/ssh_host_dsa_key
/etc/ssh_host_dsa_key is not a valid key file.
$ 




Visit your host, monkey.org