OpenSSH 4.2 released

Contributed by grey on from the w00t! dept.

The complete announcement message and details may be found here:

Downloads and more may be found from the official site:

  1. By Anonymous Coward ( on

    - Increase the default size of new RSA/DSA keys generated by ssh-keygen from 1024 to 2048 bits. RFC#14 - should change icon :) btw: are we pwn3d!?

    1. By Anonymous Coward ( on

      I agree with alot of points on that RFC list. Wouldn't mind seeing most of those imported. Some of them however are touching on old arguments :)


      1. By Anonymous Coward ( on

        And a whole lot are personal barrows he wants to push.

        I cannot find a serious point amongst the "RFCs" (whatever RFC means in this context - and it's not Really Bloody Clever!) that would have me patching or reconfigging what I do now.

        OpenBSD provides tools. Craftsmen use them. Some may choose to toss out various tools or to sharpen them in an unusual way.

        Personal choice is not hampered. He can still shoot himself in the foot if he likes or waste bullets on the clouds. So can anybody.

        The default settings are good enough for most and hey, if somebody exploits something he wanted changed then he can boast widely.

        Meanwhile the real world goes on.

        1. By Anonymous Coward ( on

          talk, talk... it seems that ssh4.2 is imported in -stable(3.7)

          1. By Brad ( brad at comstyle dot com on

            OpenSSH releases are put into the -stable branches no matter what. .. from stable.html "As an exception to the above rules, OpenSSH release versions will be merged into the patch branch."

        2. By Anonymous Coward ( on

          Most of the RFCs on that page are stupid and pointless, and are about personal preference rather than being something that should be incorporated as default for all users.

          1. By Anonymous Coward ( on

            It however does contain some valid points. You could of course call every setting a matter of personal preference, but some things mentioned in that list really do make sense

            1. By Anonymous Coward ( on

              You mean like turning off the system beep ?

              1. By Anonymous Coward ( on

                like be able to set to not decrease ttl when forwarding packets, not tu much with pf's scrub minttl.

              2. By tedu ( on

                if you learn to type correctly, you don't have to hear the beeps. :)

    2. By Anonymous Coward ( on

      Some of those opinions are kind of strange. For instance, the argument for bzip. It says that bzip has "better performance". (a direct quote) By this they mean it compresses better. But AFAIK it also is slower and uses more memory. They've neglected to mention that.

      Some of them may be valid points, but as has been mentioned, these are mostly minor stylistic issues.

  2. By Alan Post ( on

    i think the note about delayed zlib compression until after authentication is a perfect example of layered security.

    we've had two zlib security problems recently, there might or might not be more of them.

    but for ssh, we now have an option to just ignore compression in the most critical part of ssh, during authentication.

    with or without recent zlib problems, the openssh team just factored out code from this critical path. so future problems won't be the kind of issue that past problems have been (for zlib+openssh).

    this kind of layered thinking about security, exploits, and safety is just amazing. particularly when it is applied to an existing codebase in real-world situations.


    1. By Anonymous Coward ( on

      of course you can ask why it wasn't implementing in the begining ;) if you are realy paranoid you wouldn't fully trust some 3-rd part code.

  3. By Anonymous Coward ( on

    1. By Anonymous Coward ( on

      Did Cisco finally fire you?

      I don't like rants with grammatical errors, as I don't like code with errors. Especially if it is intended. That should say enough. You either are good at coding (or ranting for that matter) or you do something else with your life. Get a life!

    2. By Anonymous Coward ( on

      >Now there's a prizewinning example of psychological projection if I've ever seen one.

      back at ya buddy :)

    3. By Charles ( on

      D+, for effort.

      Where'd you cut and paste this from? That sounds suspiciously like some 1950's anti-communist rant, but I can't quite put my finger on the source. The grammer indicates you cut-and-pasted "OpenBSD developers" in for some other phrase like "communist philosophy". "Developers" is plural, but you consistantly follow it with singular verb forms.

      The style is also reminiscent of late 19th Century pamphleteers, who just adored making their tracts look intelligent by overusing a thesaurus but not following the basics of grammar and style. There are a lot of big words, but no point is ever actually made.

      Just curious.

      1. By Anonymous Coward ( on

        It looks like something that was generated by Scott Pakin's automatic complaint-letter generator:

        Of course you'll get a different text from it, but some sentences reappear.

        So all in all it is just a cheap troll ;-)

        1. By Anonymous Coward ( on

          LOL, that's exactly it...

        2. By Anonymous Coward ( on

          LOL, never heard of that site before :)

      2. By sng ( on

        I thought he was just channeling Theodore Kaczynski.

    4. By Clay Dowling ( on

      Sounds like somebody's been self-medicating again, or maybe more to the point he's stopped taking them completely.

      Would the decent humanitarian thing to do be to track down that IP address and send the boys in white coats for our friend, until he gets back to something like balance?

    5. By tedu ( on

  4. By Biff ( on

    From the announcement I gathered two things: if you update, you should also update any <3.5 systems or you won't be able to connect, seems like a flag day in that respect, and no announcement of a built in method to defeat brute force connections.

    For me, my standard method is to use pf to allow ssh connections from addresses or networks I know I'm going to be at (work, family, etc). But I have to advise people with student systems that allow ssh from the Internet at large. What is the best way today, and is their thought to an IP address lockout ot tarpit for repeat connections that are guessing passwords?

    1. By m0rf ( on

      from and elaborated on in pf.conf(5):

      pass in on $ext_if proto tcp to $ext_if port ssh flags S/SA \
      keep state (max-src-conn-rate 10/60, overload <scanners>)
      block in on $ext_if proto tcp from <scanners> to $ext_if port ssh

      changing your rate as need be.
      was added in 3.7.

      1. By m0rf ( on

        and if their packet filter doesn't support rate limiting/isn't pf, perhaps its time to advise an upgrade.


