On Fri, May 25, 2018 at 3:07 PM, Andre McCurdy <armccu...@gmail.com> wrote: > DSA keys have been deprecated for some time: > > https://www.gentoo.org/support/news-items/2015-08-13-openssh-weak-keys.html
Ping. Any issues with this? > Signed-off-by: Andre McCurdy <armccu...@gmail.com> > --- > meta/recipes-connectivity/openssh/openssh/sshd_check_keys | 8 -------- > meta/recipes-connectivity/openssh/openssh/sshd_config | 1 - > meta/recipes-connectivity/openssh/openssh_7.6p1.bb | 1 - > 3 files changed, 10 deletions(-) > > diff --git a/meta/recipes-connectivity/openssh/openssh/sshd_check_keys > b/meta/recipes-connectivity/openssh/openssh/sshd_check_keys > index 5463b1a..be2e2ec 100644 > --- a/meta/recipes-connectivity/openssh/openssh/sshd_check_keys > +++ b/meta/recipes-connectivity/openssh/openssh/sshd_check_keys > @@ -60,9 +60,6 @@ done > HOST_KEY_RSA=$(grep ^HostKey "${sshd_config}" | grep _rsa_ | tail -1 | awk ' > { print $2 } ') > [ -z "${HOST_KEY_RSA}" ] && HOST_KEY_RSA=$(grep HostKey "${sshd_config}" | > grep _rsa_ | tail -1 | awk ' { print $2 } ') > [ -z "${HOST_KEY_RSA}" ] && HOST_KEY_RSA=$SYSCONFDIR/ssh_host_rsa_key > -HOST_KEY_DSA=$(grep ^HostKey "${sshd_config}" | grep _dsa_ | tail -1 | awk ' > { print $2 } ') > -[ -z "${HOST_KEY_DSA}" ] && HOST_KEY_DSA=$(grep HostKey "${sshd_config}" | > grep _dsa_ | tail -1 | awk ' { print $2 } ') > -[ -z "${HOST_KEY_DSA}" ] && HOST_KEY_DSA=$SYSCONFDIR/ssh_host_dsa_key > HOST_KEY_ECDSA=$(grep ^HostKey "${sshd_config}" | grep _ecdsa_ | tail -1 | > awk ' { print $2 } ') > [ -z "${HOST_KEY_ECDSA}" ] && HOST_KEY_ECDSA=$(grep HostKey "${sshd_config}" > | grep _ecdsa_ | tail -1 | awk ' { print $2 } ') > [ -z "${HOST_KEY_ECDSA}" ] && HOST_KEY_ECDSA=$SYSCONFDIR/ssh_host_ecdsa_key > @@ -79,12 +76,7 @@ if [ ! -f $HOST_KEY_ECDSA ]; then > echo " generating ssh ECDSA key..." > generate_key $HOST_KEY_ECDSA ecdsa > fi > -if [ ! -f $HOST_KEY_DSA ]; then > - echo " generating ssh DSA key..." > - generate_key $HOST_KEY_DSA dsa > -fi > if [ ! -f $HOST_KEY_ED25519 ]; then > echo " generating ssh ED25519 key..." > generate_key $HOST_KEY_ED25519 ed25519 > fi > - > diff --git a/meta/recipes-connectivity/openssh/openssh/sshd_config > b/meta/recipes-connectivity/openssh/openssh/sshd_config > index 31fe5d9..b7c3ccd 100644 > --- a/meta/recipes-connectivity/openssh/openssh/sshd_config > +++ b/meta/recipes-connectivity/openssh/openssh/sshd_config > @@ -22,7 +22,6 @@ Protocol 2 > #HostKey /etc/ssh/ssh_host_key > # HostKeys for protocol version 2 > #HostKey /etc/ssh/ssh_host_rsa_key > -#HostKey /etc/ssh/ssh_host_dsa_key > #HostKey /etc/ssh/ssh_host_ecdsa_key > #HostKey /etc/ssh/ssh_host_ed25519_key > > diff --git a/meta/recipes-connectivity/openssh/openssh_7.6p1.bb > b/meta/recipes-connectivity/openssh/openssh_7.6p1.bb > index e11e8d7..a527a7c 100644 > --- a/meta/recipes-connectivity/openssh/openssh_7.6p1.bb > +++ b/meta/recipes-connectivity/openssh/openssh_7.6p1.bb > @@ -110,7 +110,6 @@ do_install_append () { > install -m 644 ${D}${sysconfdir}/ssh/sshd_config > ${D}${sysconfdir}/ssh/sshd_config_readonly > sed -i '/HostKey/d' ${D}${sysconfdir}/ssh/sshd_config_readonly > echo "HostKey /var/run/ssh/ssh_host_rsa_key" >> > ${D}${sysconfdir}/ssh/sshd_config_readonly > - echo "HostKey /var/run/ssh/ssh_host_dsa_key" >> > ${D}${sysconfdir}/ssh/sshd_config_readonly > echo "HostKey /var/run/ssh/ssh_host_ecdsa_key" >> > ${D}${sysconfdir}/ssh/sshd_config_readonly > echo "HostKey /var/run/ssh/ssh_host_ed25519_key" >> > ${D}${sysconfdir}/ssh/sshd_config_readonly > > -- > 1.9.1 > -- _______________________________________________ Openembedded-core mailing list Openembedded-core@lists.openembedded.org http://lists.openembedded.org/mailman/listinfo/openembedded-core