forked from rpms/openssh
Make default key sizes configurable in sshd-keygen
Resolves: RHEL-26454 Signed-off-by: Zoltan Fridrich <zfridric@redhat.com>
This commit is contained in:
parent
7fedb4cdc0
commit
01178d1eef
@ -804,6 +804,8 @@ test -f %{sysconfig_anaconda} && \
|
|||||||
* Thu May 02 2024 Zoltan Fridrich <zfridric@redhat.com> - 8.7p1-40
|
* Thu May 02 2024 Zoltan Fridrich <zfridric@redhat.com> - 8.7p1-40
|
||||||
- Correctly audit hostname and IP address
|
- Correctly audit hostname and IP address
|
||||||
Resolves: RHEL-22316
|
Resolves: RHEL-22316
|
||||||
|
- Make default key sizes configurable in sshd-keygen
|
||||||
|
Resolves: RHEL-26454
|
||||||
|
|
||||||
* Wed Apr 24 2024 Dmitry Belyavskiy <dbelyavs@redhat.com> - 8.7p1-39
|
* Wed Apr 24 2024 Dmitry Belyavskiy <dbelyavs@redhat.com> - 8.7p1-39
|
||||||
- Use FIPS-compatible API for key derivation
|
- Use FIPS-compatible API for key derivation
|
||||||
|
12
sshd-keygen
12
sshd-keygen
@ -9,8 +9,14 @@ case $KEYTYPE in
|
|||||||
if [[ -r "$FIPS" && $(cat $FIPS) == "1" ]]; then
|
if [[ -r "$FIPS" && $(cat $FIPS) == "1" ]]; then
|
||||||
exit 0
|
exit 0
|
||||||
fi ;;
|
fi ;;
|
||||||
"rsa") ;; # always ok
|
"rsa")
|
||||||
"ecdsa") ;;
|
if [[ ! -z $SSH_RSA_BITS ]]; then
|
||||||
|
SSH_KEYGEN_OPTIONS="-b $SSH_RSA_BITS"
|
||||||
|
fi ;; # always ok
|
||||||
|
"ecdsa")
|
||||||
|
if [[ ! -z $SSH_ECDSA_BITS ]]; then
|
||||||
|
SSH_KEYGEN_OPTIONS="-b $SSH_ECDSA_BITS"
|
||||||
|
fi ;;
|
||||||
*) # wrong argument
|
*) # wrong argument
|
||||||
exit 12 ;;
|
exit 12 ;;
|
||||||
esac
|
esac
|
||||||
@ -25,7 +31,7 @@ fi
|
|||||||
rm -f $KEY{,.pub}
|
rm -f $KEY{,.pub}
|
||||||
|
|
||||||
# create new keys
|
# create new keys
|
||||||
if ! $KEYGEN -q -t $KEYTYPE -f $KEY -C '' -N '' >&/dev/null; then
|
if ! $KEYGEN -q -t $KEYTYPE $SSH_KEYGEN_OPTIONS -f $KEY -C '' -N '' >&/dev/null; then
|
||||||
exit 1
|
exit 1
|
||||||
fi
|
fi
|
||||||
|
|
||||||
|
Loading…
Reference in New Issue
Block a user