Simon Tatham
08f1e2a506
Add an option to disable the dynamic host key policy.
...
This mitigates CVE-2020-14002: if you're in the habit of clicking OK
to unknown host keys (the TOFU policy - trust on first use), then an
active attacker looking to exploit that policy to substitute their own
host key in your first connection to a server can use the host key
algorithm order in your KEXINIT to (not wholly reliably) detect
whether you have a key already stored for this host, and if so, abort
their attack to avoid giving themself away.
However, for users who _don't_ use the TOFU policy and instead check
new host keys out of band, the dynamic policy is more useful. So it's
provided as a configurable option.
2020-06-21 16:39:47 +01:00
..
2019-09-08 20:29:21 +01:00
2020-06-21 16:39:47 +01:00
2020-06-21 16:39:47 +01:00
2007-01-07 10:17:12 +00:00
2019-09-08 20:29:21 +01:00
2019-03-18 20:32:55 +00:00
2007-01-07 10:17:12 +00:00
2005-10-04 14:13:28 +00:00
2007-01-07 10:17:12 +00:00
2005-10-04 14:13:28 +00:00
2005-10-04 14:13:28 +00:00
2007-01-07 10:17:12 +00:00
2019-09-08 20:29:21 +01:00
2019-03-16 12:25:23 +00:00
2007-01-07 10:17:12 +00:00
2007-01-07 10:17:12 +00:00
2019-09-08 20:29:21 +01:00
2019-03-18 20:32:55 +00:00
2007-02-06 22:39:15 +00:00
2019-09-08 20:29:21 +01:00
2019-03-16 12:25:23 +00:00
2017-09-13 19:26:28 +01:00
2019-03-18 21:53:45 +00:00
2019-09-08 20:29:21 +01:00
2019-03-18 22:02:13 +00:00
2017-05-07 16:29:01 +01:00
2019-03-16 12:25:23 +00:00
2019-03-18 20:32:55 +00:00
2018-11-03 13:45:00 +00:00
2019-09-08 20:29:21 +01:00
2019-09-08 20:29:21 +01:00
2020-02-09 08:51:37 +00:00
2019-09-09 19:12:02 +01:00
2019-09-08 20:29:21 +01:00
2019-10-14 19:42:37 +01:00
2020-06-14 15:49:36 +01:00
2019-10-14 19:42:37 +01:00
2019-09-08 20:29:21 +01:00
2019-03-26 00:27:04 +00:00
2020-06-21 16:39:47 +01:00
2019-03-16 12:25:23 +00:00
2019-09-08 20:29:21 +01:00
2019-10-14 19:42:37 +01:00
2019-10-14 19:42:37 +01:00
2019-09-08 20:29:21 +01:00
2020-02-09 08:51:37 +00:00
2019-03-16 12:25:23 +00:00
2019-09-08 20:29:21 +01:00
2010-12-27 00:24:48 +00:00
2018-11-03 13:47:29 +00:00
2019-09-08 20:29:21 +01:00
2020-02-09 08:51:37 +00:00
2020-02-09 08:51:37 +00:00
2019-09-08 20:29:21 +01:00
2020-02-09 08:19:21 +00:00
2019-09-08 20:29:21 +01:00
2019-09-08 20:29:21 +01:00
2019-09-08 20:29:21 +01:00
2019-09-08 20:29:21 +01:00
2020-06-14 15:49:36 +01:00
2020-02-09 08:19:21 +00:00
2019-01-20 17:09:24 +00:00
2019-10-14 19:42:37 +01:00
2020-02-09 08:19:21 +00:00
2017-02-14 23:25:25 +00:00
2019-09-08 20:29:21 +01:00
2019-09-08 20:29:21 +01:00
2019-09-08 20:29:21 +01:00