Jochen Bern
2025-Jun-30 12:14 UTC
Config to have "ssh too-old-host" error out (with chosen message, and sans actual connection attempt)?
On 30.06.25 13:46, Darren Tucker wrote:> On Mon, 30 Jun 2025 at 20:47, Jochen Bern <Jochen.Bern at binect.de<mailto:Jochen.Bern at binect.de>> wrote: > > ProxyCommand seems to be unable, too (because its output apparently gets > > swallowed *entirely* by ssh). > > Its stdout does (since that's its purpose), but its stderr doesn't: > > $ cat config > ProxyCommand sh -c "echo use foo instead >&2" > > $ ssh -F ./config foo bar > use foo instead > Connection closed by UNKNOWN port 65535Ah ... I had tried ">&2" *without* the additional explicit shell (level), thanks, works well. Whereas ... On 30.06.25 13:09, Brian Candler wrote:> You could abuse a text config setting, like > > Host foobar > Hostname ": You should use ssh -O PubkeyAcceptedAlgorithms=+ssh-rsa"[...]> Or BindInterface... these both escape the ANSI control sequences I added, alas. :-3> Although of course, if that were the problem, you could simply apply the > fix instead: > PubkeyAcceptedAlgorithms +ssh-rsaI've been using a bunch of *those* for quite a while (because I upped my *default* cryptalgorithm settings *beyond* the back-then OS policy some time ago), and the OS Changelog's remark "OpenSSL libs now refuse signatures with SHA-1" doesn't seem to be *exact*, either. What I've seen getting *specifically* refused is my local ssh-agent signing with the older (and shorter, 4kb) RSA keypair, but that doesn't seem to explain *all* the now-failing connections, either ... Thanks again, -- Jochen Bern Systemingenieur Binect GmbH -------------- next part -------------- A non-text attachment was scrubbed... Name: smime.p7s Type: application/pkcs7-signature Size: 4336 bytes Desc: S/MIME Cryptographic Signature URL: <http://lists.mindrot.org/pipermail/openssh-unix-dev/attachments/20250630/943add57/attachment.p7s>
Brian Candler
2025-Jun-30 12:34 UTC
Config to have "ssh too-old-host" error out (with chosen message, and sans actual connection attempt)?
On 30/06/2025 13:14, Jochen Bern wrote:> What I've seen getting *specifically* refused is my local ssh-agent > signing with the older (and shorter, 4kb) RSA keypair, but that > doesn't seem to explain *all* the now-failing connections, eitherThat's a 4096-bit RSA key pair? Can you show the error message? If it's not fixed by ? PubkeyAcceptedAlgorithms +ssh-rsa ? HostKeyAlgorithms +ssh-rsa then I don't know what the issue might be. The other settings I sometimes need to apply for very old network devices are ? KexAlgorithms +diffie-hellman-group1-sha1,diffie-hellman-group14-sha1 ? Ciphers +aes256-cbc,3des-cbc