PSA: Your ssh-rsa keys are NOT BEING DEPRECATED in ssh. ssh-rsa keys can, under the hood, be used with SHA-1 signatures or SHA-256 signatures. You don't need to regenerate your keys. No need to panic.
-
Show this thread
-
OpenSSH's advisory was worded very confusingly, but the way it works is that ssh-rsa *keys* can be used with both the ssh-rsa *algorithm* and the rsa-sha2-256 *algorithm*. If both sides support the latter then there is no SHA1 in use.
2 replies 6 retweets 40 likesShow this thread -
Replying to @marcan42
I tried to migrate to ed25519 keys years ago but every once in a while I find some service or app that only supports rsa...
1 reply 0 retweets 2 likes -
Replying to @jessidhia
I largely migrated to ed25519 (with a backup RSA key for that stuff)... then migrated back to RSA to be able to use YubiKeys.
1 reply 0 retweets 5 likes -
-
Replying to @11rcombs @jessidhia
It seems YubiKey 5.2.3 and above *finally* support ed25519. I might have to upgrade...
1 reply 0 retweets 0 likes -
Like, this is new as of this year.
1 reply 0 retweets 0 likes -
Unfortunately Yubico doesn't tell you which firmware version you will get if you order...
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.