FS#58273 - [openssh] add moduli to backup()

Attached to Project: Arch Linux
Opened by Jan Veen (jan.veen) - Thursday, 19 April 2018, 12:50 GMT
Last edited by Gaetan Bisson (vesath) - Thursday, 19 April 2018, 15:40 GMT
Task Type Feature Request
Category Packages: Core
Status Closed
Assigned To Gaetan Bisson (vesath)
Architecture All
Severity Low
Priority Normal
Reported Version
Due in Version Undecided
Due Date Undecided
Percent Complete 100%
Votes 0
Private No

Details

Description:

I want to provide my own moduli on my SSH servers and clients.
However, since the /etc/ssh/moduli file is not listed in the
backup() array of the PKGBUILD, this is practically not possible.

It would be nice if you could insert the file as backup.

Thank you.
This task depends upon

Closed by  Gaetan Bisson (vesath)
Thursday, 19 April 2018, 15:40 GMT
Reason for closing:  Duplicate
Comment by Gaetan Bisson (vesath) - Thursday, 19 April 2018, 15:39 GMT
See  FS#45072 ,  FS#45515  and  FS#46952 .

Short answer is no: those values are carefully selected by upstream for security and interoperability. Changing them should definitely not be allowed as part the normal user configuration of OpenSSH. And if you really know what you are doing and want to bring your own changes to the moduli values, well you might as well just recompile openssh to your taste...

Loading...