OpenSSH 10.4/10.4p1 Released
openssh.org
OpenSSH 10.4/10.4p1 Released
1–10 of 25 posts
Re: OpenSSH 10.4/10.4p1 Released
#2Re: OpenSSH 10.4/10.4p1 Released
#3When pq key agreement was added in 2019, it took almost 3 years for it to become enabled by default. This isn't criticism, just an observation. I don't have a pressing need for pq sigs. Always happy for new OpenSSH releases though!
Re: OpenSSH 10.4/10.4p1 Released
#4Re: OpenSSH 10.4/10.4p1 Released
#5HTML version of release notes: * https://www.openssh.org/releasenotes.html#10.4
Anyone know if these projects accept PRs to improve these kinds of things, like legibility? Or is it a point of pride?
Re: OpenSSH 10.4/10.4p1 Released
#6Among other changes 10.4 adds post-quantum keys (composite ML-DSA 44 and Ed25519), not enabled by default. When pq key agreement was added in 2019, it took almost 3 years for it to become enabled by default. This isn't criticism, just an observation. I don't have a pressing need for pq sigs. Always happy for new OpenSSH releases though!
The draft was only published a few months ago:
* https://datatracker.ietf.org/doc/draft-miller-sshm-mldsa44-e...
The draft is a 'personal document', so not associated with the IETF/WG.
Re: OpenSSH 10.4/10.4p1 Released
#7Is hmac-sha1 and umac-64 still enabled by default?
* https://man.openbsd.org/ssh_config.5#MACs
* https://man.openbsd.org/sshd_config.5#MACs
ETM, encrypt-than-mac, variants are at the front of the preference list.
Re: OpenSSH 10.4/10.4p1 Released
#8HTML version of release notes: * https://www.openssh.org/releasenotes.html#10.4
Still looks like ascii, doesn’t automatically wrap, nor is it responsive. Anyone know if these projects accept PRs to improve these kinds of things, like legibility? Or is it a point of pride?
Re: OpenSSH 10.4/10.4p1 Released
#9HTML version of release notes: * https://www.openssh.org/releasenotes.html#10.4
Still looks like ascii, doesn’t automatically wrap, nor is it responsive. Anyone know if these projects accept PRs to improve these kinds of things, like legibility? Or is it a point of pride?
https://github.com/openbsd/www/commits/master
My experience is that minor improvements tend to get accepted if they come with a solid technical motivation and fits into the overall OpenBSD mindset and ecosystem. If the change is simply justified by "best practices" and is rather large, then the conservative choice of just leaving things as they are usually prevail.
For example, I think I have seen two proposals for major overhauls of the OpenBSD.org homepage by "outsiders" over the last three years or so and they were both rejected. However, as you can see by the commit log, minor improvements (including presentation ones) happen all the time.
Re: OpenSSH 10.4/10.4p1 Released
#10HTML version of release notes: * https://www.openssh.org/releasenotes.html#10.4
Still looks like ascii, doesn’t automatically wrap, nor is it responsive. Anyone know if these projects accept PRs to improve these kinds of things, like legibility? Or is it a point of pride?