Discussion
Loading...

#Tag

Log in
  • About
  • Code of conduct
  • Privacy
  • Users
  • Instances
  • About Bonfire
Pascal boosted
Paul D. Ouderkirk
Paul D. Ouderkirk
@pdo@infosec.exchange  ·  activity timestamp 2 months ago

If you used OpenSSH this year you should consider kicking a few bucks over to The OpenBSD Foundation (https://www.openbsdfoundation.org/donations.html)

The few, the proud, the people who donate to open source projects.

#openbsd #openssh

  • Copy link
  • Flag this post
  • Block
Paul D. Ouderkirk
Paul D. Ouderkirk
@pdo@infosec.exchange  ·  activity timestamp 2 months ago

If you used OpenSSH this year you should consider kicking a few bucks over to The OpenBSD Foundation (https://www.openbsdfoundation.org/donations.html)

The few, the proud, the people who donate to open source projects.

#openbsd #openssh

  • Copy link
  • Flag this post
  • Block
Stefano Marinelli boosted
Michael Dexter
Michael Dexter
@dexter@bsd.network  ·  activity timestamp 2 months ago

Community events like the BSDCons do not have quarterly earnings reports but can sure be at the mercy of them.

If you organization benefits from free software like #BSD Unix and projects Iike #OpenSSH, please make their support a permanent part of your budgets.

❤️

  • Copy link
  • Flag this post
  • Block
Michael Dexter
Michael Dexter
@dexter@bsd.network  ·  activity timestamp 2 months ago

Community events like the BSDCons do not have quarterly earnings reports but can sure be at the mercy of them.

If you organization benefits from free software like #BSD Unix and projects Iike #OpenSSH, please make their support a permanent part of your budgets.

❤️

  • Copy link
  • Flag this post
  • Block
Michael Dexter and 1 other boosted
h3artbl33d :openbsd: :antifa:
h3artbl33d :openbsd: :antifa:
@h3artbl33d@exquisite.social  ·  activity timestamp 3 months ago

New blogpost: Using a SSH config: https://h3artbl33d.nl/blog/using-a-ssh-config

#OpenBSD #OpenSSH #SysAdmin

  • Copy link
  • Flag this post
  • Block
h3artbl33d :openbsd: :antifa:
h3artbl33d :openbsd: :antifa:
@h3artbl33d@exquisite.social  ·  activity timestamp 3 months ago

New blogpost: Using a SSH config: https://h3artbl33d.nl/blog/using-a-ssh-config

#OpenBSD #OpenSSH #SysAdmin

  • Copy link
  • Flag this post
  • Block
Michael Dexter and 1 other boosted
Peter N. M. Hansteen
Peter N. M. Hansteen
@pitrh@mastodon.social  ·  activity timestamp 3 months ago

OpenSSH 10.2 released https://www.undeadly.org/cgi?action=article;sid=20251010131052 #openbsd #openssh #ssh #security #networking #login #trickery #shell #tunneling

  • Copy link
  • Flag this post
  • Block
Peter N. M. Hansteen
Peter N. M. Hansteen
@pitrh@mastodon.social  ·  activity timestamp 3 months ago

OpenSSH 10.2 released https://www.undeadly.org/cgi?action=article;sid=20251010131052 #openbsd #openssh #ssh #security #networking #login #trickery #shell #tunneling

  • Copy link
  • Flag this post
  • Block
Stefano Marinelli boosted
ティージェーグレェ
ティージェーグレェ
@teajaygrey@snac.bsd.cafe  ·  activity timestamp 3 months ago

I submitted a Pull Request to update MacPorts' OpenSSH to 10.1p1 here:

https://github.com/macports/macports-ports/pull/28592

GitHub Continuous Integration checks passed OK!

Alas, the agent.patch that iamGavinJ had created, doesn't apply cleanly, in large part because ssh-agent.c has been reworked significantly with this release.

Subsequently, I closed this previous Pull Request: https://github.com/macports/macports-ports/pull/28592 not because I didn't want to restore that functionality to launchd, but because it will require more effort than I can give such things at this time.

But, check out these improvements to ssh-agent from the OpenSSH 10.1 release notes:

"ssh-agent(1)](https://man.openbsd.org/ssh-agent.1), sshd(8): move agent listener sockets from /tmp to
under ~/.ssh/agent for both ssh-agent(1) and forwarded sockets
in sshd(8).

This ensures processes that have restricted filesystem access
that includes /tmp do not ambiently have the ability to use keys
in an agent.

Moving the default directory has the consequence that the OS will
no longer clean up stale agent sockets, so ssh-agent now gains
this ability.

To support $HOME on NFS, the socket path includes a truncated
hash of the hostname. ssh-agent will, by default, only clean up
sockets from the same hostname.

ssh-agent(1) gains some new flags: -U suppresses the automatic
cleanup of stale sockets when it starts. -u forces a cleanup
without keeping a running agent, -uu forces a cleanup that ignores
the hostname. -T makes ssh-agent put the socket back in /tmp."

Anyway, I updated this as well:

https://trac.macports.org/ticket/72482

I should probably actually close this ticket now that I think of it (fingers crossed that adding that to the PR is sufficient, since I forgot to add that note to the commit message as is typically preferred: https://trac.macports.org/ticket/73084).

#OpenSSH #MacPorts #SecureShell #macOS #encryption #security #infosec

  • Copy link
  • Flag this post
  • Block
ティージェーグレェ
ティージェーグレェ
@teajaygrey@snac.bsd.cafe  ·  activity timestamp 3 months ago

I submitted a Pull Request to update MacPorts' OpenSSH to 10.1p1 here:

https://github.com/macports/macports-ports/pull/28592

GitHub Continuous Integration checks passed OK!

Alas, the agent.patch that iamGavinJ had created, doesn't apply cleanly, in large part because ssh-agent.c has been reworked significantly with this release.

Subsequently, I closed this previous Pull Request: https://github.com/macports/macports-ports/pull/28592 not because I didn't want to restore that functionality to launchd, but because it will require more effort than I can give such things at this time.

But, check out these improvements to ssh-agent from the OpenSSH 10.1 release notes:

"ssh-agent(1)](https://man.openbsd.org/ssh-agent.1), sshd(8): move agent listener sockets from /tmp to
under ~/.ssh/agent for both ssh-agent(1) and forwarded sockets
in sshd(8).

This ensures processes that have restricted filesystem access
that includes /tmp do not ambiently have the ability to use keys
in an agent.

Moving the default directory has the consequence that the OS will
no longer clean up stale agent sockets, so ssh-agent now gains
this ability.

To support $HOME on NFS, the socket path includes a truncated
hash of the hostname. ssh-agent will, by default, only clean up
sockets from the same hostname.

ssh-agent(1) gains some new flags: -U suppresses the automatic
cleanup of stale sockets when it starts. -u forces a cleanup
without keeping a running agent, -uu forces a cleanup that ignores
the hostname. -T makes ssh-agent put the socket back in /tmp."

Anyway, I updated this as well:

https://trac.macports.org/ticket/72482

I should probably actually close this ticket now that I think of it (fingers crossed that adding that to the PR is sufficient, since I forgot to add that note to the commit message as is typically preferred: https://trac.macports.org/ticket/73084).

#OpenSSH #MacPorts #SecureShell #macOS #encryption #security #infosec

  • Copy link
  • Flag this post
  • Block
Stefano Marinelli boosted
Peter N. M. Hansteen
Peter N. M. Hansteen
@pitrh@mastodon.social  ·  activity timestamp 3 months ago

OpenSSH 10.1 released https://www.undeadly.org/cgi?action=article;sid=20251006105328 #openbsd #openssh #ssh #security #newrelease #crypto #cryptography #securelogin #networking #freesoftware #libresoftware

OpenSSH 10.1 released

  • Copy link
  • Flag this post
  • Block
Peter N. M. Hansteen
Peter N. M. Hansteen
@pitrh@mastodon.social  ·  activity timestamp 3 months ago

OpenSSH 10.1 released https://www.undeadly.org/cgi?action=article;sid=20251006105328 #openbsd #openssh #ssh #security #newrelease #crypto #cryptography #securelogin #networking #freesoftware #libresoftware

OpenSSH 10.1 released

  • Copy link
  • Flag this post
  • Block
Stefano Marinelli boosted
Peter N. M. Hansteen
Peter N. M. Hansteen
@pitrh@mastodon.social  ·  activity timestamp 5 months ago

Post-Quantum Cryptography Advice Added to OpenSSH Website https://www.undeadly.org/cgi?action=article;sid=20250811110058 #openbsd #openssh #ssh #cryptography #postquantum #postq #crypto #security #libresoftware #freesoftware #bsd

  • Copy link
  • Flag this post
  • Block
Peter N. M. Hansteen
Peter N. M. Hansteen
@pitrh@mastodon.social  ·  activity timestamp 5 months ago

Post-Quantum Cryptography Advice Added to OpenSSH Website https://www.undeadly.org/cgi?action=article;sid=20250811110058 #openbsd #openssh #ssh #cryptography #postquantum #postq #crypto #security #libresoftware #freesoftware #bsd

  • Copy link
  • Flag this post
  • Block
Daniel Ares
Daniel Ares
@daniel@federation.network  ·  activity timestamp 5 months ago

Wth, after the latest #OpenSSH update the daemon only listens on IPv6 addresses? Is that just me? Lol #Linux

lsof -i -n -P | grep sshd
sshd 63245 root 3u IPv6 4882 0t0 TCP *:22 (LISTEN)
  • Copy link
  • Flag this post
  • Block
Stefano Marinelli boosted
Peter N. M. Hansteen
Peter N. M. Hansteen
@pitrh@mastodon.social  ·  activity timestamp 6 months ago

Recent new features in OpenSSH https://www.undeadly.org/cgi?action=article;sid=20250802084523 #openbsd #openssh #ssh #newfeatures #development #security #freesoftware #libresoftware #crypto #cryptography

  • Copy link
  • Flag this post
  • Block
Peter N. M. Hansteen
Peter N. M. Hansteen
@pitrh@mastodon.social  ·  activity timestamp 6 months ago

Recent new features in OpenSSH https://www.undeadly.org/cgi?action=article;sid=20250802084523 #openbsd #openssh #ssh #newfeatures #development #security #freesoftware #libresoftware #crypto #cryptography

  • Copy link
  • Flag this post
  • Block
Dendrobatus Azureus
Dendrobatus Azureus
@Dendrobatus_Azureus@mastodon.bsd.cafe  ·  activity timestamp 8 months ago

An unimportant remnant of the past has been removed from open SSH;
DSA.

Read about it in this article the next article linked will show you that it has been removed finally

#SSH#openSSH#DSA #programming #coding#OpenSource#openBSD#BSD#secureShell#Infosec

https://undeadly.org/cgi?action=article;sid=20240111105900

 The image shows a screenshot of a webpage from the OpenBSD Journal. The top of the page features a black background with a logo on the left, depicting a cartoonish sun with guns, and the text "OpenBSD Journal" in light blue. Below the logo, navigation links are visible: Home, Archives, About, Submit, Story, Create Account, and Login.

The main content of the page is a news article titled "DSA removal from OpenSSH" in large, light blue text. The article was contributed by "rueda" on January 11, 2024, from the "going-dept." The article states that the OpenSSH project has announced the timeline for the removal of DSA support from OpenSSH. It mentions that OpenSSH plans to remove support for DSA, as specified in the SSHv2 protocol, which is limited to a 160-bit private key with an estimated security level of less than or equal to 80 bits. The article also notes that OpenSSH has disabled DSA keys by default and that DSA is optional support for them.

The bottom of the page shows the URL "undeady.org/cgi?act" and a navigation bar with three vertical lines, a home icon, a back arrow, and a menu icon. The battery icon in the top right corner indicates 82% battery life, and the time is 03:31.

 Ovis2-8B

🌱 Energy used: 0.353 Wh
The image shows a screenshot of a webpage from the OpenBSD Journal. The top of the page features a black background with a logo on the left, depicting a cartoonish sun with guns, and the text "OpenBSD Journal" in light blue. Below the logo, navigation links are visible: Home, Archives, About, Submit, Story, Create Account, and Login. The main content of the page is a news article titled "DSA removal from OpenSSH" in large, light blue text. The article was contributed by "rueda" on January 11, 2024, from the "going-dept." The article states that the OpenSSH project has announced the timeline for the removal of DSA support from OpenSSH. It mentions that OpenSSH plans to remove support for DSA, as specified in the SSHv2 protocol, which is limited to a 160-bit private key with an estimated security level of less than or equal to 80 bits. The article also notes that OpenSSH has disabled DSA keys by default and that DSA is optional support for them. The bottom of the page shows the URL "undeady.org/cgi?act" and a navigation bar with three vertical lines, a home icon, a back arrow, and a menu icon. The battery icon in the top right corner indicates 82% battery life, and the time is 03:31. Ovis2-8B 🌱 Energy used: 0.353 Wh
The image shows a screenshot of a webpage from the OpenBSD Journal. The top of the page features a black background with a logo on the left, depicting a cartoonish sun with guns, and the text "OpenBSD Journal" in light blue. Below the logo, navigation links are visible: Home, Archives, About, Submit, Story, Create Account, and Login. The main content of the page is a news article titled "DSA removal from OpenSSH" in large, light blue text. The article was contributed by "rueda" on January 11, 2024, from the "going-dept." The article states that the OpenSSH project has announced the timeline for the removal of DSA support from OpenSSH. It mentions that OpenSSH plans to remove support for DSA, as specified in the SSHv2 protocol, which is limited to a 160-bit private key with an estimated security level of less than or equal to 80 bits. The article also notes that OpenSSH has disabled DSA keys by default and that DSA is optional support for them. The bottom of the page shows the URL "undeady.org/cgi?act" and a navigation bar with three vertical lines, a home icon, a back arrow, and a menu icon. The battery icon in the top right corner indicates 82% battery life, and the time is 03:31. Ovis2-8B 🌱 Energy used: 0.353 Wh
Dendrobatus Azureus
Dendrobatus Azureus
@Dendrobatus_Azureus@mastodon.bsd.cafe replied  ·  activity timestamp 8 months ago

This article shows that DSA has finally been removed

#SSH#openSSH#DSA #programming #coding#OpenSource#openBSD#BSD#secureShell#Infosec

https://undeadly.org/cgi?action=article;sid=20250507010932

 The image shows a screenshot of a webpage from the OpenBSD Journal. The top of the page displays the title "OpenBSD Journal" with a logo featuring a stylized sun. Below the title, there are navigation links including Home, Archives, About, Submit Story, Create Account, and Login. The main content of the page is a news article titled "DSA signature support removed from OpenSSH," contributed by rueda on 2025-05-06. The article states that Damien Miller has completed the removal of DSA signature support from OpenSSH, listing the modified and removed files. The CVSROOT and Module name are also provided. The log message confirms the removal of DSA signature support. The editors encourage readers to ensure the removal is complete. The latest articles section lists other recent news items, including a commit of the LLDP daemon and tool and a call for testing the last bits of DSA. The webpage's URL is undeadly.org/cgi?act, and the battery level is at 82%.

 Ovis2-8B

🌱 Energy used: 0.249 Wh
The image shows a screenshot of a webpage from the OpenBSD Journal. The top of the page displays the title "OpenBSD Journal" with a logo featuring a stylized sun. Below the title, there are navigation links including Home, Archives, About, Submit Story, Create Account, and Login. The main content of the page is a news article titled "DSA signature support removed from OpenSSH," contributed by rueda on 2025-05-06. The article states that Damien Miller has completed the removal of DSA signature support from OpenSSH, listing the modified and removed files. The CVSROOT and Module name are also provided. The log message confirms the removal of DSA signature support. The editors encourage readers to ensure the removal is complete. The latest articles section lists other recent news items, including a commit of the LLDP daemon and tool and a call for testing the last bits of DSA. The webpage's URL is undeadly.org/cgi?act, and the battery level is at 82%. Ovis2-8B 🌱 Energy used: 0.249 Wh
The image shows a screenshot of a webpage from the OpenBSD Journal. The top of the page displays the title "OpenBSD Journal" with a logo featuring a stylized sun. Below the title, there are navigation links including Home, Archives, About, Submit Story, Create Account, and Login. The main content of the page is a news article titled "DSA signature support removed from OpenSSH," contributed by rueda on 2025-05-06. The article states that Damien Miller has completed the removal of DSA signature support from OpenSSH, listing the modified and removed files. The CVSROOT and Module name are also provided. The log message confirms the removal of DSA signature support. The editors encourage readers to ensure the removal is complete. The latest articles section lists other recent news items, including a commit of the LLDP daemon and tool and a call for testing the last bits of DSA. The webpage's URL is undeadly.org/cgi?act, and the battery level is at 82%. Ovis2-8B 🌱 Energy used: 0.249 Wh
  • Copy link
  • Flag this comment
  • Block

bonfire.cafe

A space for Bonfire maintainers and contributors to communicate

bonfire.cafe: About · Code of conduct · Privacy · Users · Instances
Bonfire social · 1.0.1-beta.35 no JS en
Automatic federation enabled
Log in
  • Explore
  • About
  • Members
  • Code of Conduct