SSH Public Key Authentication: Transitioning from ssh-rsa to SHA-2 signatures in OpenSSH 8.8+
26K reputation · 22 Sept 2024, 22:37 UTC
Signature Algorithm Deprecation
OpenSSH 8.8 and later versions have disabled the ssh-rsa signature algorithm by default. This change targets the use of SHA-1 for signatures during the authentication handshake, though the underlying RSA key pair remains valid if a more secure signature scheme is employed.
Compatibility Constraints
Systems maintaining legacy clients or servers may encounter authentication failures when the client only supports SHA-1 signatures. While the PubkeyAcceptedAlgorithms configuration can explicitly re-enable ssh-rsa to restore connectivity, this introduces known security vulnerabilities back into the handshake process.
There is a need to determine the most efficient path for transitioning existing RSA keys to rsa-sha2-256 or rsa-sha2-512 without forcing a full regeneration of all user keys across a distributed environment.
- Does the server-side
PubkeyAcceptedAlgorithmssetting override the client's preference for SHA-2 signatures when both are available? - What is the impact on authentication latency when the server must negotiate multiple signature schemes for a single RSA key?