[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Bug#234627: ssh-copy-id should default to id_dsa.pub, not identity.pub



Package: ssh
Version: 1:3.6.1p2-12
Severity: normal

ssh config script now recommends protocol2_only; if the user follows the
recommendation then id_dsa.pub should be the default public key.

Could ssh-copy-id check for the existence of id_dsa.pub *first*, and use
that rather than identity.pub if it exists?  Or could it just use
id_dsa.pub?

Or, to get really fancy, it could check which key version the target
machine accepts when connecting.

In any case, defaulting to identity.pub without any systemwide way to
change the default seems to me to be the wrong approach.

-- System Information:
Debian Release: testing/unstable
  APT prefers unstable
  APT policy: (500, 'unstable')
Architecture: i386 (i686)
Kernel: Linux 2.6.3-joehill
Locale: LANG=en_US, LC_CTYPE=en_US

Versions of packages ssh depends on:
ii  adduser                     3.51         Add and remove users and groups
hi  debconf                     1.4.10       Debian configuration management sy
ii  dpkg                        1.10.18      Package maintenance system for Deb
hi  libc6                       2.3.2.ds1-11 GNU C Library: Shared libraries an
ii  libpam-modules              0.76-15      Pluggable Authentication Modules f
ii  libpam-runtime              0.76-15      Runtime support for the PAM librar
ii  libpam0g                    0.76-15      Pluggable Authentication Modules l
ii  libssl0.9.7                 0.9.7c-5     SSL shared libraries
ii  libwrap0                    7.6-ipv6.1-3 Wietse Venema's TCP wrappers libra
ii  zlib1g                      1:1.2.1-4    compression library - runtime

-- debconf information:
  ssh/insecure_rshd: 
  ssh/privsep_ask: true
* ssh/user_environment_tell: 
* ssh/forward_warning: 
* ssh/insecure_telnetd: 
  ssh/new_config: true
* ssh/use_old_init_script: true
* ssh/SUID_client: true
* ssh/privsep_tell: 
  ssh/ssh2_keys_merged: 
* ssh/protocol2_only: true
  ssh/encrypted_host_key_but_no_keygen: 
* ssh/run_sshd: true

Attachment: signature.asc
Description: Digital signature


Reply to: