FS#58273 - [openssh] add moduli to backup()
Attached to Project:
Arch Linux
Opened by Jan Veen (jan.veen) - Thursday, 19 April 2018, 12:50 GMT
Last edited by Gaetan Bisson (vesath) - Thursday, 19 April 2018, 15:40 GMT
Opened by Jan Veen (jan.veen) - Thursday, 19 April 2018, 12:50 GMT
Last edited by Gaetan Bisson (vesath) - Thursday, 19 April 2018, 15:40 GMT
|
Details
Description:
I want to provide my own moduli on my SSH servers and clients. However, since the /etc/ssh/moduli file is not listed in the backup() array of the PKGBUILD, this is practically not possible. It would be nice if you could insert the file as backup. Thank you. |
This task depends upon
FS#45072,FS#45515andFS#46952.Short answer is no: those values are carefully selected by upstream for security and interoperability. Changing them should definitely not be allowed as part the normal user configuration of OpenSSH. And if you really know what you are doing and want to bring your own changes to the moduli values, well you might as well just recompile openssh to your taste...