git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: Issues with newest version of openssh 8.8p1-1

From
Bryan Turner <bturner@atlassian.com>
Date
Sep 28, 2021, 07:32 UTC
Message-ID
<CAGyf7-FBgmRTmjKFjMi2p5MArGEQh9a4Z6RA6FO-2U4D5jGnmA@mail.gmail.com>
In-Reply-To
<CAKcQ8=cyq46=eF8NZtUifmfHgWUphmHPYh4s3oQrHjiX2nqEmQ@mail.gmail.com>

On Mon, Sep 27, 2021 at 11:40 PM Kevin Kendzia <kevin.kendzia@googlemail.com> wrote:

Show 20 quoted lines
>
> Updated to openssh (8.8p1-1) and git didn't get the keys anymore.
> Couldn't pull or push. After reverting back to 8.7p1-2 it works as
> intended.
>
> Thank you for filling out a Git bug report!
> Please answer the following questions to help us understand your issue.
>
> What did you do before the bug happened? (Steps to reproduce your issue)
> Updated system packages (openssh)
> What did you expect to happen? (Expected behavior)
> Can git pull without issues
> What happened instead? (Actual behavior)
> Permission Denied due to key error
> What's different between what you expected and what actually happened?
> I couldn't push pull whatever because the keys haven't been recognized somehow
> Anything else you want to add:
> I reverted from openssh 8.8p1-1 to 8.7p1-2 to make it work again
> Please review the rest of the bug report below.
> You can delete any lines you don't wish to share.

Ultimately this isn't a Git issue; it's an SSH issue. My guess would be that upgrading to OpenSSH 8.8 picks up the change to stop using RSA signatures using SHA-1 hashes by default.[1]

You can update your ~/.ssh/config to add these lines to revert that
and allow using those keys again:
Host old-host
     HostkeyAlgorithms +ssh-rsa
     PubkeyAcceptedAlgorithms +ssh-rsa

With that said, though, if possible a better solution is to generate new SSH keys using ECDSA, Ed25519 or another stronger signature and switch to those.

Hope this helps! Bryan

[1] https://www.openssh.com/releasenotes.html
Previous: Kevin KendziaNext: brian m. carlson
Message 2 of 5 in “Issues with newest version of openssh 8.8p1-1”
  1. Kevin KendziaSep 28, 2021
  2. Bryan TurnerSep 28, 2021
  3. brian m. carlsonSep 29, 2021
  4. Carlo ArenasSep 28, 2021
  5. Bagas SanjayaSep 28, 2021

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.