OpenSSH's advisory was worded very confusingly, but the way it works is that ssh-rsa *keys* can be used with both the ssh-rsa *algorithm* and the rsa-sha2-256 *algorithm*. If both sides support the latter then there is no SHA1 in use.
-
-
Show this thread
-
This also applies to hardware tokens, e.g. YubiKeys. The token doesn't know nor care how its ssh-rsa support is being used. It works fine. Use `ssh -vvv` to check for rsa-sha2-512 or rsa-sha2-256.
Show this thread
End of conversation
New conversation -
-
-
Thanks for the clarification!!! Indeed the original post was quite confusing!!!
Thanks. Twitter will use this to make your timeline better. UndoUndo
-
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.