From: | Akshay Joshi <akshay(dot)joshi(at)enterprisedb(dot)com> |
---|---|
To: | Dave Page <dpage(at)pgadmin(dot)org> |
Cc: | Sven <svoop_6cedifwf9e(at)delirium(dot)ch>, pgAdmin Support <pgadmin-support(at)postgresql(dot)org> |
Subject: | Re: SSH tunnel key exchange methods |
Date: | 2015-11-30 05:11:35 |
Message-ID: | CANxoLDdJT6KXXTZ860DdopC8Txb6Pd2yX3NvZudb_HhwYxrU+w@mail.gmail.com |
Views: | Raw Message | Whole Thread | Download mbox | Resend email |
Thread: | |
Lists: | pgadmin-hackers pgadmin-support |
Hi Dave
On Fri, Nov 27, 2015 at 3:01 PM, Dave Page <dpage(at)pgadmin(dot)org> wrote:
> On Fri, Nov 27, 2015 at 9:23 AM, Sven <svoop_6cedifwf9e(at)delirium(dot)ch>
> wrote:
> >> The key exchange methods offered when opening an SSH tunnel are all
> >> SHA1 and therefore too weak:
> >>
> >> [sshd] fatal: Unable to negotiate with xxx.xxx.xxx.xxx: no matching
> >> key exchange method found. Their offer:
> >> diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1,
> >> diffie-hellman-group1-sha1 [preauth]
> >
> > Any news on this? If there's no easy way to add safer kexes, I suggest
> > you disable the SSH feature altogether. SHA1 is dead and IMO nobody
> > should trust a connection established with SHA1 kexes in order to talk
> > to databases.
>
> Akshay, you know that code best of all. How do we enable safer kexes?
>
Today I'll look into it on priority and update accordingly.
>
> --
> Dave Page
> Blog: http://pgsnake.blogspot.com
> Twitter: @pgsnake
>
> EnterpriseDB UK: http://www.enterprisedb.com
> The Enterprise PostgreSQL Company
>
--
*Akshay Joshi*
*Principal Software Engineer *
*Phone: +91 20-3058-9517Mobile: +91 976-788-8246*
From | Date | Subject | |
---|---|---|---|
Next Message | Akshay Joshi | 2015-11-30 12:57:34 | Re: SSH tunnel key exchange methods |
Previous Message | Ashesh Vashi | 2015-11-28 14:49:51 | pgAdmin 4 commit: Load collection.js along with the node.js from browse |
From | Date | Subject | |
---|---|---|---|
Next Message | Akshay Joshi | 2015-11-30 12:57:34 | Re: SSH tunnel key exchange methods |
Previous Message | Per Wigren | 2015-11-27 10:57:31 | Re: Greenplum warning message |