upstream: add security key types to list of keys allowed to act as

CAs; spotted by Ron Frederick

OpenBSD-Commit-ID: 9bb0dfff927b4f7aa70679f983f84c69d45656c3
This commit is contained in:
djm@openbsd.org 2019-12-10 22:43:19 +00:00 committed by Damien Miller
parent 516605f2d5
commit 75f7f22a43
1 changed files with 4 additions and 2 deletions

View File

@ -1,4 +1,4 @@
/* $OpenBSD: myproposal.h,v 1.61 2019/11/12 19:33:08 markus Exp $ */ /* $OpenBSD: myproposal.h,v 1.62 2019/12/10 22:43:19 djm Exp $ */
/* /*
* Copyright (c) 2000 Markus Friedl. All rights reserved. * Copyright (c) 2000 Markus Friedl. All rights reserved.
@ -145,7 +145,9 @@
/* Not a KEX value, but here so all the algorithm defaults are together */ /* Not a KEX value, but here so all the algorithm defaults are together */
#define SSH_ALLOWED_CA_SIGALGS \ #define SSH_ALLOWED_CA_SIGALGS \
HOSTKEY_ECDSA_METHODS \ HOSTKEY_ECDSA_METHODS \
USERKEY_ECDSA_SK_METHODS \
"ssh-ed25519," \ "ssh-ed25519," \
"sk-ssh-ed25519@openssh.com," \
"rsa-sha2-512," \ "rsa-sha2-512," \
"rsa-sha2-256," \ "rsa-sha2-256," \
"ssh-rsa" "ssh-rsa"
@ -194,7 +196,7 @@
#define KEX_CLIENT_ENCRYPT KEX_SERVER_ENCRYPT #define KEX_CLIENT_ENCRYPT KEX_SERVER_ENCRYPT
#define KEX_CLIENT_MAC KEX_SERVER_MAC #define KEX_CLIENT_MAC KEX_SERVER_MAC
#define SSH_ALLOWED_CA_SIGALGS "ssh-ed25519" #define SSH_ALLOWED_CA_SIGALGS "ssh-ed25519,sk-ssh-ed25519@openssh.com"
#endif /* WITH_OPENSSL */ #endif /* WITH_OPENSSL */