#sshfp — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #sshfp, aggregated by home.social.
-
SSHFP – Fingerprint-Verifizierung via DNS
https://friendica.ambag.es/display/e0590d38-126a-5141-40f1-2e3121457649
-
SSHFP – Fingerprint-Verifizierung via DNS
https://friendica.ambag.es/display/e0590d38-126a-5141-40f1-2e3121457649
-
Happy to report that a longstanding @Codeberg feature request has been resolved -
codeberg.orgnow provides #SSHFP records over #DNSSEC, giving an automated level of trust to first time connections.https://codeberg.org/Codeberg/Community/issues/89#issuecomment-18936449
-
Happy to report that a longstanding @Codeberg feature request has been resolved -
codeberg.orgnow provides #SSHFP records over #DNSSEC, giving an automated level of trust to first time connections.https://codeberg.org/Codeberg/Community/issues/89#issuecomment-18936449
-
Happy to report that a longstanding @Codeberg feature request has been resolved -
codeberg.orgnow provides #SSHFP records over #DNSSEC, giving an automated level of trust to first time connections.https://codeberg.org/Codeberg/Community/issues/89#issuecomment-18936449
-
Happy to report that a longstanding @Codeberg feature request has been resolved -
codeberg.orgnow provides #SSHFP records over #DNSSEC, giving an automated level of trust to first time connections.https://codeberg.org/Codeberg/Community/issues/89#issuecomment-18936449
-
Happy to report that a longstanding @Codeberg feature request has been resolved -
codeberg.orgnow provides #SSHFP records over #DNSSEC, giving an automated level of trust to first time connections.https://codeberg.org/Codeberg/Community/issues/89#issuecomment-18936449
-
-
-
-
-
-
In ssh_config, why does VerifyHostKeyDNS default to "no"? Combined with the default StrictHostKeyChecking set to "ask", this means that manual host key verification by the user is preferred to automatic host key checking via dns. I suspect 90% of "unrecognised host key" prompts are accepted blindly and never manually validated, which seems like lower security than automatic host key validation. Is there a security risk to SSHFP record checking?
-
In ssh_config, why does VerifyHostKeyDNS default to "no"? Combined with the default StrictHostKeyChecking set to "ask", this means that manual host key verification by the user is preferred to automatic host key checking via dns. I suspect 90% of "unrecognised host key" prompts are accepted blindly and never manually validated, which seems like lower security than automatic host key validation. Is there a security risk to SSHFP record checking?
-
In ssh_config, why does VerifyHostKeyDNS default to "no"? Combined with the default StrictHostKeyChecking set to "ask", this means that manual host key verification by the user is preferred to automatic host key checking via dns. I suspect 90% of "unrecognised host key" prompts are accepted blindly and never manually validated, which seems like lower security than automatic host key validation. Is there a security risk to SSHFP record checking?
-
In ssh_config, why does VerifyHostKeyDNS default to "no"? Combined with the default StrictHostKeyChecking set to "ask", this means that manual host key verification by the user is preferred to automatic host key checking via dns. I suspect 90% of "unrecognised host key" prompts are accepted blindly and never manually validated, which seems like lower security than automatic host key validation. Is there a security risk to SSHFP record checking?
-
In ssh_config, why does VerifyHostKeyDNS default to "no"? Combined with the default StrictHostKeyChecking set to "ask", this means that manual host key verification by the user is preferred to automatic host key checking via dns. I suspect 90% of "unrecognised host key" prompts are accepted blindly and never manually validated, which seems like lower security than automatic host key validation. Is there a security risk to SSHFP record checking?
-
I have #SSHFP records set up for my various hosts now. Could this be the end of host key mismatch errors?
-
I have #SSHFP records set up for my various hosts now. Could this be the end of host key mismatch errors?
-
I have #SSHFP records set up for my various hosts now. Could this be the end of host key mismatch errors?
-
I have #SSHFP records set up for my various hosts now. Could this be the end of host key mismatch errors?
-
I have #SSHFP records set up for my various hosts now. Could this be the end of host key mismatch errors?
-
@ruawhitepaw #Github is also missing #SSHFP DNS records and #DNSSEC, which would help protect there users accessing it via git over SSH!
-
@ruawhitepaw #Github is also missing #SSHFP DNS records and #DNSSEC, which would help protect there users accessing it via git over SSH!
-
@ruawhitepaw #Github is also missing #SSHFP DNS records and #DNSSEC, which would help protect there users accessing it via git over SSH!
-
@ruawhitepaw #Github is also missing #SSHFP DNS records and #DNSSEC, which would help protect there users accessing it via git over SSH!
-
@ruawhitepaw #Github is also missing #SSHFP DNS records and #DNSSEC, which would help protect there users accessing it via git over SSH!
-
Special thanks to @gehaxelt, who is the co-author of the paper that is based on his previous work on identifying #SSHFP misconfigurations, and Peter Mayer. Also many thanks to the organizers and the great audience at #ACSAC for an overall great conference!
🔗 full paper can be read here: https://publikationen.bibliothek.kit.edu/1000186330
-
Special thanks to @gehaxelt, who is the co-author of the paper that is based on his previous work on identifying #SSHFP misconfigurations, and Peter Mayer. Also many thanks to the organizers and the great audience at #ACSAC for an overall great conference!
🔗 full paper can be read here: https://publikationen.bibliothek.kit.edu/1000186330
-
Special thanks to @gehaxelt, who is the co-author of the paper that is based on his previous work on identifying #SSHFP misconfigurations, and Peter Mayer. Also many thanks to the organizers and the great audience at #ACSAC for an overall great conference!
🔗 full paper can be read here: https://publikationen.bibliothek.kit.edu/1000186330
-
Special thanks to @gehaxelt, who is the co-author of the paper that is based on his previous work on identifying #SSHFP misconfigurations, and Peter Mayer. Also many thanks to the organizers and the great audience at #ACSAC for an overall great conference!
🔗 full paper can be read here: https://publikationen.bibliothek.kit.edu/1000186330
-
The #paper “Fix It - If you Can! Towards Understanding the Impact of Tool Support and Domain Owners’ Reactions to SSHFP Misconfigurations" by Anne Hennig, Sebastian Neef, and Peter Mayer has been accepted for presentation at the @ACSAC_Conf! The paper sent notifications to domain owners with misconfigured #SSHFP records, investigating the effect of tool support. While the sender of the #notification itself has no effect, the results suggest that tool support might increase remediation when the sender of the notification is different than the institution providing the tool. By analyzing domain owners’ responses to the authors' notification, multiple reasons for non-remediation were identified, supporting the argument that remediation rate should not be considered a success measure for a notification campaign but instead individual challenges faced by domain owners should be taken into account. ACSAC will take place December 8 to 12, 2025, in Honolulu, Hawaii, USA: https://www.acsac.org/
@Aryderwood @gehaxelt -
The #paper “Fix It - If you Can! Towards Understanding the Impact of Tool Support and Domain Owners’ Reactions to SSHFP Misconfigurations" by Anne Hennig, Sebastian Neef, and Peter Mayer has been accepted for presentation at the @ACSAC_Conf! The paper sent notifications to domain owners with misconfigured #SSHFP records, investigating the effect of tool support. While the sender of the #notification itself has no effect, the results suggest that tool support might increase remediation when the sender of the notification is different than the institution providing the tool. By analyzing domain owners’ responses to the authors' notification, multiple reasons for non-remediation were identified, supporting the argument that remediation rate should not be considered a success measure for a notification campaign but instead individual challenges faced by domain owners should be taken into account. ACSAC will take place December 8 to 12, 2025, in Honolulu, Hawaii, USA: https://www.acsac.org/
@Aryderwood @gehaxelt -
The #paper “Fix It - If you Can! Towards Understanding the Impact of Tool Support and Domain Owners’ Reactions to SSHFP Misconfigurations" by Anne Hennig, Sebastian Neef, and Peter Mayer has been accepted for presentation at the @ACSAC_Conf! The paper sent notifications to domain owners with misconfigured #SSHFP records, investigating the effect of tool support. While the sender of the #notification itself has no effect, the results suggest that tool support might increase remediation when the sender of the notification is different than the institution providing the tool. By analyzing domain owners’ responses to the authors' notification, multiple reasons for non-remediation were identified, supporting the argument that remediation rate should not be considered a success measure for a notification campaign but instead individual challenges faced by domain owners should be taken into account. ACSAC will take place December 8 to 12, 2025, in Honolulu, Hawaii, USA: https://www.acsac.org/
@Aryderwood @gehaxelt -
The #paper “Fix It - If you Can! Towards Understanding the Impact of Tool Support and Domain Owners’ Reactions to SSHFP Misconfigurations" by Anne Hennig, Sebastian Neef, and Peter Mayer has been accepted for presentation at the @ACSAC_Conf! The paper sent notifications to domain owners with misconfigured #SSHFP records, investigating the effect of tool support. While the sender of the #notification itself has no effect, the results suggest that tool support might increase remediation when the sender of the notification is different than the institution providing the tool. By analyzing domain owners’ responses to the authors' notification, multiple reasons for non-remediation were identified, supporting the argument that remediation rate should not be considered a success measure for a notification campaign but instead individual challenges faced by domain owners should be taken into account. ACSAC will take place December 8 to 12, 2025, in Honolulu, Hawaii, USA: https://www.acsac.org/
@Aryderwood @gehaxelt -
The #paper “Fix It - If you Can! Towards Understanding the Impact of Tool Support and Domain Owners’ Reactions to SSHFP Misconfigurations" by Anne Hennig, Sebastian Neef, and Peter Mayer has been accepted for presentation at the @ACSAC_Conf! The paper sent notifications to domain owners with misconfigured #SSHFP records, investigating the effect of tool support. While the sender of the #notification itself has no effect, the results suggest that tool support might increase remediation when the sender of the notification is different than the institution providing the tool. By analyzing domain owners’ responses to the authors' notification, multiple reasons for non-remediation were identified, supporting the argument that remediation rate should not be considered a success measure for a notification campaign but instead individual challenges faced by domain owners should be taken into account. ACSAC will take place December 8 to 12, 2025, in Honolulu, Hawaii, USA: https://www.acsac.org/
@Aryderwood @gehaxelt -
Как FreeIPA защищает SSH от MITM-атак
Привет, Хабр! Сегодня мы предлагаем погрузиться во внутреннюю кухню протокола SSH, заострив особое внимание на его интеграции с доменом FreeIPA. Настройка такого взаимодействия будет интересна администраторам, привыкшим к централизованному управлению Windows-серверами и рабочими местами, входящими в состав MS AD. Развитие нашей продуктовой линейки включает глубокий анализ технологического стека, и мы хотим поделиться с читателями результатами своих исследований. Как известно, время — деньги, поэтому инженеры стараются настраивать удаленный доступ везде, где только можно, чтобы ничего не администрировать ногами.
https://habr.com/ru/companies/astralinux/articles/946002/
#ssh #freeipa #ald_pro #mitm #ключи #dh #sshfp #kerberos #sssd #диффихеллман
-
Как FreeIPA защищает SSH от MITM-атак
Привет, Хабр! Сегодня мы предлагаем погрузиться во внутреннюю кухню протокола SSH, заострив особое внимание на его интеграции с доменом FreeIPA. Настройка такого взаимодействия будет интересна администраторам, привыкшим к централизованному управлению Windows-серверами и рабочими местами, входящими в состав MS AD. Развитие нашей продуктовой линейки включает глубокий анализ технологического стека, и мы хотим поделиться с читателями результатами своих исследований. Как известно, время — деньги, поэтому инженеры стараются настраивать удаленный доступ везде, где только можно, чтобы ничего не администрировать ногами.
https://habr.com/ru/companies/astralinux/articles/946002/
#ssh #freeipa #ald_pro #mitm #ключи #dh #sshfp #kerberos #sssd #диффихеллман
-
Как FreeIPA защищает SSH от MITM-атак
Привет, Хабр! Сегодня мы предлагаем погрузиться во внутреннюю кухню протокола SSH, заострив особое внимание на его интеграции с доменом FreeIPA. Настройка такого взаимодействия будет интересна администраторам, привыкшим к централизованному управлению Windows-серверами и рабочими местами, входящими в состав MS AD. Развитие нашей продуктовой линейки включает глубокий анализ технологического стека, и мы хотим поделиться с читателями результатами своих исследований. Как известно, время — деньги, поэтому инженеры стараются настраивать удаленный доступ везде, где только можно, чтобы ничего не администрировать ногами.
https://habr.com/ru/companies/astralinux/articles/946002/
#ssh #freeipa #ald_pro #mitm #ключи #dh #sshfp #kerberos #sssd #диффихеллман
-
@letoams Similarly may publish #SSHFP record of #gitlab users. Both gitlab.isc.org and gitlab.nic.cz are on DNSSEC signed domains. Gitlab knows SSH keys of their users, very often used. They could export them for outer verification, just some way of mapping SSH key to username is required. We have that concepts for OPENPGPKEY and SMIMEA records. Would a new draft for SSHFP make sense too? Should it include public key directly in DNSKEY/KEY record?
-
@letoams Similarly may publish #SSHFP record of #gitlab users. Both gitlab.isc.org and gitlab.nic.cz are on DNSSEC signed domains. Gitlab knows SSH keys of their users, very often used. They could export them for outer verification, just some way of mapping SSH key to username is required. We have that concepts for OPENPGPKEY and SMIMEA records. Would a new draft for SSHFP make sense too? Should it include public key directly in DNSKEY/KEY record?
-
@letoams Similarly may publish #SSHFP record of #gitlab users. Both gitlab.isc.org and gitlab.nic.cz are on DNSSEC signed domains. Gitlab knows SSH keys of their users, very often used. They could export them for outer verification, just some way of mapping SSH key to username is required. We have that concepts for OPENPGPKEY and SMIMEA records. Would a new draft for SSHFP make sense too? Should it include public key directly in DNSKEY/KEY record?
-
@letoams Similarly may publish #SSHFP record of #gitlab users. Both gitlab.isc.org and gitlab.nic.cz are on DNSSEC signed domains. Gitlab knows SSH keys of their users, very often used. They could export them for outer verification, just some way of mapping SSH key to username is required. We have that concepts for OPENPGPKEY and SMIMEA records. Would a new draft for SSHFP make sense too? Should it include public key directly in DNSKEY/KEY record?
-
@letoams Similarly may publish #SSHFP record of #gitlab users. Both gitlab.isc.org and gitlab.nic.cz are on DNSSEC signed domains. Gitlab knows SSH keys of their users, very often used. They could export them for outer verification, just some way of mapping SSH key to username is required. We have that concepts for OPENPGPKEY and SMIMEA records. Would a new draft for SSHFP make sense too? Should it include public key directly in DNSKEY/KEY record?
-
@soatok @letoams For example mastodns.net is a Fedi server on #DNSSEC signed zone, algorithms 13 or 8 used only. I see no weakness if they would allow publishing of keys, RFC 7929 style. But with #SSHFP RR digests, to prove my identity of git ssh signed software, just like you have proposed. Just choose well your TLD and that's it. Append only log is important to prove no other CA made cert for my name. But we have just one parent domain key in #DNS. Give it a chance, it is not so bad. 😀