all lists on lists.proxmox.com
 help / color / mirror / Atom feed
* [pve-devel] [RFC container] setup: remove deprecated dsa from ssh host key generation
@ 2025-06-25  9:56 Daniel Kral
  2025-06-26 11:36 ` Wolfgang Bumiller
  0 siblings, 1 reply; 9+ messages in thread
From: Daniel Kral @ 2025-06-25  9:56 UTC (permalink / raw)
  To: pve-devel

OpenSSH 10.0 removes support for the DSA signature algorithm [0], which
is the base version that will be shipped for Debian 13 trixie [1]. Since
it has been marked deprecated for some time and generating DSA
signatures with OpenSSH 10.0 will fail, remove it.

[0] https://www.openssh.com/txt/release-10.0
[1] https://www.debian.org/releases/trixie/release-notes/whats-new.en.html

Signed-off-by: Daniel Kral <d.kral@proxmox.com>
---
Sending it as a RFC as I'm unsure if there's any other repercussions
removing it here. AFAICS it seems this is the only site where we
generate DSA signatures.

 src/PVE/LXC/Setup/Base.pm | 1 -
 1 file changed, 1 deletion(-)

diff --git a/src/PVE/LXC/Setup/Base.pm b/src/PVE/LXC/Setup/Base.pm
index 6bdfb8d..dbfc775 100644
--- a/src/PVE/LXC/Setup/Base.pm
+++ b/src/PVE/LXC/Setup/Base.pm
@@ -646,7 +646,6 @@ sub ssh_host_key_types_to_generate {
 
     return {
         rsa => 'ssh_host_rsa_key',
-        dsa => 'ssh_host_dsa_key',
         ecdsa => 'ssh_host_ecdsa_key',
         ed25519 => 'ssh_host_ed25519_key',
     };
-- 
2.39.5



_______________________________________________
pve-devel mailing list
pve-devel@lists.proxmox.com
https://lists.proxmox.com/cgi-bin/mailman/listinfo/pve-devel


^ permalink raw reply	[flat|nested] 9+ messages in thread

end of thread, other threads:[~2025-06-27 10:11 UTC | newest]

Thread overview: 9+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2025-06-25  9:56 [pve-devel] [RFC container] setup: remove deprecated dsa from ssh host key generation Daniel Kral
2025-06-26 11:36 ` Wolfgang Bumiller
2025-06-27  5:04   ` Fabian Grünbichler
2025-06-27  8:20     ` Daniel Kral
2025-06-27  8:46       ` Fabian Grünbichler
2025-06-27  8:59         ` Daniel Kral
2025-06-27  9:06           ` Fabian Grünbichler
2025-06-27  9:44         ` Daniel Kral
2025-06-27 10:11           ` Fabian Grünbichler

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.
Service provided by Proxmox Server Solutions GmbH | Privacy | Legal