#OpenSSH

2025-12-12

¿Quieres aprender a usar *certificados* con SSH?

He aquí mi artículo más reciente: blog.woralelandia.com/certific

#openssh #fedora #howto

2025-12-11

Just learned about the existence of #PuttyCAC and that (supposedly) the Putty project rejected implementing OpenSC smartcard support.

So now the only way you can use a smartcard (aka. a yubikey) for SSH authentication with #FileZilla and/or #WinSCP is to use it as both still do NOT support #OpenSSH agent but only the Putty Pageant.

So if anyone else is looking for a way to use their smartcard with WinSCP or FileZilla, install OpenSC, reboot, install Putty-CAC, start Putty-CAC|s pageant.

N-gated Hacker Newsngate
2025-11-30

OpenBSD: It's like the cool kid at the party who just can't stop telling everyone how secure and free it is, but really just wants you to notice its tattoo. 🤔✨ Two remote holes in the default install? Wow, must be a record-breaking snooze fest! 💤🔒
openbsd.org/

2025-11-28
Hoje eu aprendi que, com OpenSSH, basta um mero ssh -D 9999 -N destino — ou com autossh se quiser retomar automaticamente a conexão que cair — para poder usar a porta local (9999 no exemplo) como SOCKS proxy saindo pela máquina destino especificada! :mindBlown:

Vivendo e aprendendo, temos que tirar o chapéu também para o pessoal do #OpenBSD que presenteia o mundo ao desenvolver essa maravilha.

#OpenSSH #SSH #blambers #TIL #softwareLivre #freeSoftware
Hackerman - meme do seriado Mr. Robot - Eliot Alderson (Rami Malek) posa com cara de esperto e braços cruzados, vestindo sua blusa de moletom com gorro, e mochila, em montagem que lembra o vídeo Kung Fury com um fundo 3D colorido e, em primeiro plano, a palavra Hackerman em letras brilhosas
2025-11-24

Returning out of necessity to a project I abandoned to stop myself from getting an aneurysm and immediately I find a comment reminding me why I abandoned it in the first place:

OpenSSH is really super GODDAMN PICKY about motherfucking permissions

The entire path, INCLUDING WHEREEVER THE GODDAMN MOUNT IS MOUNTED ALL THE WAY UP TO /

must be owned by root. FUCK!

Thou shalt not provide #OpenSSH authorized_keys in a path of your choosing, that's a crime!

Paul D. Ouderkirkpdo@infosec.exchange
2025-11-21

If you used OpenSSH this year you should consider kicking a few bucks over to The OpenBSD Foundation (openbsdfoundation.org/donation)

The few, the proud, the people who donate to open source projects.

#openbsd #openssh

2025-11-20

Joost van Dijk from @yubico tells us about #OpenSSH combined with the #FIDO standard at the @nluug #najaarsconferentie. This info applies on any FIDO #securitykey, not just #yubikey.

#opensourceconference #Linuxconference #conference #conferentie #NLUUG #nluug25nj #hardwarekey

Joost van Dijk presenting in front of a slide about hardware-protecting SSH keys.
Michael Dexterdexter@bsd.network
2025-11-18

Community events like the BSDCons do not have quarterly earnings reports but can sure be at the mercy of them.

If you organization benefits from free software like #BSD Unix and projects Iike #OpenSSH, please make their support a permanent part of your budgets.

❤️

2025-11-09

I am currently updating my small OpenWrt routers from v23 to v24. Unfortunately, this is not so easy: Dropbear does not support ED25519 in v24. RSA (with a key length of 4096) takes several seconds per login, which is too slow when using Ansible.

#OpenWrt #Dropbear #OpenSSH #Fail #Anaible #RSA #ED25519 #Networking #HomeLab

2025-11-01

#Linux Trick 17: Wenn man in seinen #OpenSSH Server Banner einen kurzen Abriss über den Tiananmen Square oder Gulang Gong platziert, trennt (TCP Reset) die Great Firewall of China die Verbindungen der SSH-Scanner, bevor sie irgendwelche Passwörter ausprobieren können.

2025-10-28

@JustinDerrick @harrysintonen And lo! It appears to have returned :blobastonished:

#openssh

2025-10-27

Still no official statement from #openssh project about the status of openssh.com domain - this is getting a bit silly now.

2025-10-27

Wondering if someone forgot to renew their domain at openssh.com as it appears to have recently changed hands and is offline…

#openssh #cybersquatting #security

Marcus Adamsgerowen
2025-10-27

That said, since modern versions of have adopted a post-quantum key exchange by default and isn't, by default at least, totally quantum safe, I wonder if it would be better to use SSH with password login disabled as a VPN instead of Wireguard. You can use the optional PSK option with Wireguard to attain some level of PQ security, but it's not 100% because of the default handshake.

Just thinking out loud.

2025-10-25

Openssh.com is down - apparently this is due to a domain move to another registrar. The site being down has caused some concern about something malicious going on. According to the little information available currently this doesn't appear to be the case. Preferably the project themselves should come out with a clear statement about this.

EDIT: 2025-10-28 Statement from Damien Miller:

"It's fixed now.

We transferred the domain to a different registrar and they locked it for abuse when they received it. Unfortunately this happened over a weekend so it took even longer to sort out."
source: lists.mindrot.org/pipermail/op

#openssh

www.openssh.com is down:

"This site can’t provide a secure connection
www.openssh.com sent an invalid response.
ERR_SSL_PROTOCOL_ERROR"
2025-10-23

I'm not doing anything nearly cool enough to warrant this warning from the latest version of #OpenSSH...

#ssh #Linux #postquantum

A screenshot of a terminal, with white text on a dark grey background saying:
** WARNING: connection is not using a post-quantum key exchange algorithm.
** This session may be vulnerable to "store now, decrypt later" attacks.
2025-10-22

Forgot to check #OpenSSH 10.1's changelog It was released a few weeks ago and has some interesting features #PQ

* ssh(1): add a warning when the connection negotiates a non-post quantum key agreement algorithm.

This warning has been added due to the risk of "store now, decrypt later" attacks. More details at openssh.com/pq.html

This warning may be controlled via a new WarnWeakCrypto ssh_config option, defaulting to on. This option is likely to control additional weak crypto warnings in the future.

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst