{"thread":{"id":"56596","subject":"Issues with newest version of openssh 8.8p1-1","startedAt":"2021-09-28T06:40:19Z","lastAt":"2021-09-29T22:58:56Z","messageCount":5,"participants":["Kevin Kendzia","Bryan Turner","Carlo Arenas","Bagas Sanjaya","brian m. carlson"],"isPatch":false,"patchVersion":null,"patchTotal":null},"messages":[{"id":"437254","messageId":"CAKcQ8=cyq46=eF8NZtUifmfHgWUphmHPYh4s3oQrHjiX2nqEmQ@mail.gmail.com","threadId":"56596","inReplyTo":null,"subject":"Issues with newest version of openssh 8.8p1-1","fromName":"Kevin Kendzia","fromEmail":"kevin.kendzia@googlemail.com","sentAt":"2021-09-28T06:40:04Z","receivedAt":"2021-09-28T06:40:19Z","isPatch":false,"sender":{"key":"kevin.kendzia@googlemail.com","avatar":null},"body":"Updated to openssh (8.8p1-1) and git didn't get the keys anymore.\nCouldn't pull or push. After reverting back to 8.7p1-2 it works as\nintended.\n\nThank you for filling out a Git bug report!\nPlease answer the following questions to help us understand your issue.\n\nWhat did you do before the bug happened? (Steps to reproduce your issue)\nUpdated system packages (openssh)\nWhat did you expect to happen? (Expected behavior)\nCan git pull without issues\nWhat happened instead? (Actual behavior)\nPermission Denied due to key error\nWhat's different between what you expected and what actually happened?\nI couldn't push pull whatever because the keys haven't been recognized somehow\nAnything else you want to add:\nI reverted from openssh 8.8p1-1 to 8.7p1-2 to make it work again\nPlease review the rest of the bug report below.\nYou can delete any lines you don't wish to share.\n\n\n[System Info]\ngit version 2.33.0\ncpu: x86_64\nno commit associated with this build\nsizeof-long: 8\nsizeof-size_t: 8\nshell-path: /bin/sh\nuname: Linux 5.14.8-arch1-1 #1 SMP PREEMPT Sun, 26 Sep 2021 19:36:15\n+0000 x86_64\ncompiler info: gnuc: 11.1\nlibc info: glibc: 2.33\n$SHELL (typically, interactive shell): /bin/bash\n\n\n[Enabled Hooks]\n"},{"id":"437258","messageId":"CAGyf7-FBgmRTmjKFjMi2p5MArGEQh9a4Z6RA6FO-2U4D5jGnmA@mail.gmail.com","threadId":"56596","inReplyTo":"CAKcQ8=cyq46=eF8NZtUifmfHgWUphmHPYh4s3oQrHjiX2nqEmQ@mail.gmail.com","subject":"Re: Issues with newest version of openssh 8.8p1-1","fromName":"Bryan Turner","fromEmail":"bturner@atlassian.com","sentAt":"2021-09-28T07:32:05Z","receivedAt":"2021-09-28T07:32:19Z","isPatch":false,"sender":{"key":"bturner@atlassian.com","avatar":"https://gravatar.com/avatar/16bcf3167981c1ef7c804e502642366d888a35b0d0b0a4ca01fdc442aa1acb1e?d=mp&s=160"},"body":"On Mon, Sep 27, 2021 at 11:40 PM Kevin Kendzia\n<kevin.kendzia@googlemail.com> wrote:\n>\n> Updated to openssh (8.8p1-1) and git didn't get the keys anymore.\n> Couldn't pull or push. After reverting back to 8.7p1-2 it works as\n> intended.\n>\n> Thank you for filling out a Git bug report!\n> Please answer the following questions to help us understand your issue.\n>\n> What did you do before the bug happened? (Steps to reproduce your issue)\n> Updated system packages (openssh)\n> What did you expect to happen? (Expected behavior)\n> Can git pull without issues\n> What happened instead? (Actual behavior)\n> Permission Denied due to key error\n> What's different between what you expected and what actually happened?\n> I couldn't push pull whatever because the keys haven't been recognized somehow\n> Anything else you want to add:\n> I reverted from openssh 8.8p1-1 to 8.7p1-2 to make it work again\n> Please review the rest of the bug report below.\n> You can delete any lines you don't wish to share.\n\nUltimately this isn't a Git issue; it's an SSH issue. My guess would\nbe that upgrading to OpenSSH 8.8 picks up the change to stop using RSA\nsignatures using SHA-1 hashes by default.[1]\n\nYou can update your ~/.ssh/config to add these lines to revert that\nand allow using those keys again:\nHost old-host\n     HostkeyAlgorithms +ssh-rsa\n     PubkeyAcceptedAlgorithms +ssh-rsa\n\nWith that said, though, if possible a better solution is to generate\nnew SSH keys using ECDSA, Ed25519 or another stronger signature and\nswitch to those.\n\nHope this helps!\nBryan\n\n[1] https://www.openssh.com/releasenotes.html\n"},{"id":"437259","messageId":"CAPUEspinqCF7Y+Zc3VwE2wL6P8Mj7VVkjKvQk6XSzdufMmjjWQ@mail.gmail.com","threadId":"56596","inReplyTo":"CAKcQ8=cyq46=eF8NZtUifmfHgWUphmHPYh4s3oQrHjiX2nqEmQ@mail.gmail.com","subject":"Re: Issues with newest version of openssh 8.8p1-1","fromName":"Carlo Arenas","fromEmail":"carenas@gmail.com","sentAt":"2021-09-28T07:45:53Z","receivedAt":"2021-09-28T07:46:07Z","isPatch":false,"sender":{"key":"carenas@gmail.com","avatar":"https://avatars.githubusercontent.com/u/76036?v=4"},"body":"Something like `ssh -vvv user@host` would probably be useful to see\nwhere the key negotiation breaks for you, but it is unlikely to be a\nproblem with git.\n\nMy guess is that your host key is still using RSA with SHA1 and you\nhaven't updated it by following the instructions[1] OpenSSH provided\nwith their 8.3 release\n\nCarlo\n\nPS. I upgraded to OpenSSH 8.8p1 and had no problems connecting, but I\nam not on Arch, so that might be another possibility\n\n[1] https://lwn.net/Articles/821544/\n"},{"id":"437260","messageId":"6a47ba98-46f2-59fb-20b3-b9b507aac243@gmail.com","threadId":"56596","inReplyTo":"CAKcQ8=cyq46=eF8NZtUifmfHgWUphmHPYh4s3oQrHjiX2nqEmQ@mail.gmail.com","subject":"Re: Issues with newest version of openssh 8.8p1-1","fromName":"Bagas Sanjaya","fromEmail":"bagasdotme@gmail.com","sentAt":"2021-09-28T07:54:16Z","receivedAt":"2021-09-28T07:54:21Z","isPatch":false,"sender":{"key":"bagasdotme@gmail.com","avatar":"https://avatars.githubusercontent.com/u/40219486?v=4"},"body":"On 28/09/21 13.40, Kevin Kendzia wrote:\n> Updated to openssh (8.8p1-1) and git didn't get the keys anymore.\n> Couldn't pull or push. After reverting back to 8.7p1-2 it works as\n> intended.\n> \n> Thank you for filling out a Git bug report!\n> Please answer the following questions to help us understand your issue.\n> \n> What did you do before the bug happened? (Steps to reproduce your issue)\n> Updated system packages (openssh)\n> What did you expect to happen? (Expected behavior)\n> Can git pull without issues\n> What happened instead? (Actual behavior)\n> Permission Denied due to key error\n> What's different between what you expected and what actually happened?\n> I couldn't push pull whatever because the keys haven't been recognized somehow\n> Anything else you want to add:\n> I reverted from openssh 8.8p1-1 to 8.7p1-2 to make it work again\n> Please review the rest of the bug report below.\n> You can delete any lines you don't wish to share.\n> \n> \n> [System Info]\n> git version 2.33.0\n> cpu: x86_64\n> no commit associated with this build\n> sizeof-long: 8\n> sizeof-size_t: 8\n> shell-path: /bin/sh\n> uname: Linux 5.14.8-arch1-1 #1 SMP PREEMPT Sun, 26 Sep 2021 19:36:15\n> +0000 x86_64\n> compiler info: gnuc: 11.1\n> libc info: glibc: 2.33\n> $SHELL (typically, interactive shell): /bin/bash\n> \n> \n> [Enabled Hooks]\n> \n\nWhat remote you tried to push or pull from? What key do you use? If \nyou're connecting to GitHub, see [1].\n\n[1]: https://github.blog/2021-09-01-improving-git-protocol-security-github/\n\n-- \nAn old man doll... just what I always wanted! - Clara\n"},{"id":"437483","messageId":"YVTvqpjkHuB2c15l@camp.crustytoothpaste.net","threadId":"56596","inReplyTo":"CAGyf7-FBgmRTmjKFjMi2p5MArGEQh9a4Z6RA6FO-2U4D5jGnmA@mail.gmail.com","subject":"Re: Issues with newest version of openssh 8.8p1-1","fromName":"brian m. carlson","fromEmail":"sandals@crustytoothpaste.net","sentAt":"2021-09-29T22:58:50Z","receivedAt":"2021-09-29T22:58:56Z","isPatch":false,"sender":{"key":"sandals@crustytoothpaste.net","avatar":"https://avatars.githubusercontent.com/u/497054?v=4"},"body":"On 2021-09-28 at 07:32:05, Bryan Turner wrote:\n> Ultimately this isn't a Git issue; it's an SSH issue. My guess would\n> be that upgrading to OpenSSH 8.8 picks up the change to stop using RSA\n> signatures using SHA-1 hashes by default.[1]\n> \n> You can update your ~/.ssh/config to add these lines to revert that\n> and allow using those keys again:\n> Host old-host\n>      HostkeyAlgorithms +ssh-rsa\n>      PubkeyAcceptedAlgorithms +ssh-rsa\n\nI should point out that these algorithms are disabled by default because\nthey are a security risk.  This has been announced for a long time now\nin OpenSSH and everyone should have either switched key types or enabled\nRSA with SHA-2 or both.\n\n> With that said, though, if possible a better solution is to generate\n> new SSH keys using ECDSA, Ed25519 or another stronger signature and\n> switch to those.\n\nYou also need to contact the party operating the server to which you're\ntrying to push in this case, since it's ultimately the fact that they\ndon't support RSA with SHA-2 that's the problem.\n\nThere are a couple different providers (in my testing just this second,\nI found Bitbucket and Azure DevOps) who are still offering only the\nssh-rsa host keys (possibly with ssh-dss as well) and not offering the\nrsa-sha2-256 and rsa-sha2-512 algorithms, and only the server operator\ncan fix those.  If the server operator adds support for RSA with SHA-2,\nthen OpenSSH 8.8 will work just fine.  But otherwise, this will continue\nto be broken out of the box.\n\nBut as for client keys, I do strongly recommend Ed25519 in all cases.\nIf you have the misfortune of having to use a FIPS-compliant environment\n(which I don't recommend in any case), then use RSA with SHA-2.\n-- \nbrian m. carlson (he/him or they/them)\nToronto, Ontario, CA\n"}]}