svn commit: r294495 - in head: . crypto/openssh

Dag-Erling Smørgrav des at des.no
Fri Jan 22 09:37:52 UTC 2016


Conrad Meyer <cem at FreeBSD.org> writes:
> Are we going to maintain DSA key support after upstream deprecates it
> entirely?  And why?

I am not aware of any plans to remove DSA support.  It has simply been
disabled in the default run-time configuration - unlike, for instance,
libwrap, which was removed entirely, and SSHv1, which needs to be
enabled at compile time.  I understand that decision (although I
disagree with their justification, or at least the way it was worded),
but we still have users who use DSA keys and who will be locked out of
their systems if we disable DSA without sufficient advance warning.  I
will look into what steps can be taken to deprecate DSA without causing
our users too much inconvenience.

DES
-- 
Dag-Erling Smørgrav - des at des.no


More information about the svn-src-head mailing list