OpenSSH 6.5 released
Summary
In January 2014 OpenSSH 6.5 brought key exchange with Curve25519 and signatures with Ed25519, both developed by Daniel J. Bernstein. One reason was the Snowden revelations, since the widely used NIST curves came from an NSA employee. Ed25519 replaces ECDSA, which is vulnerable when random number generators are weak.
Ideas
- Curve parameters of unclear origin undermine trust in cryptography.
- Ed25519 needs no random number per signature and thus avoids an ECDSA weakness.
- The Snowden revelations triggered a switch to traceable methods.
- ChaCha20-Poly1305 replaces the insecure but fast RC4.
Insights
- Cryptographic methods should not only be secure but also designed traceably.
- Robustness against implementation errors is a quality feature in its own right.
Facts
- OpenSSH 6.5 introduced Curve25519 for key exchange.
- Ed25519 was added for signatures.
- Diffie-Hellman key exchange now requires at least 2048 bits instead of 1024 bits.
- Connections with RSA-MD5 signatures from old commercial clients are rejected.
References
Critique
- The report bases its performance claim about ChaCha20 on a single test of its own.
Remarks
- Since OpenSSH 9.5, Ed25519 has been the default key type of ssh-keygen.
Recommendations
- Generate new SSH keys with ssh-keygen -t ed25519.
- Remove old DSA and short RSA keys from authorized_keys.
Links to the original source and the Web Archive open in a new tab.