[Bug 1528251] Re: WARNING: no suitable primes in /etc/ssh/primes

Dimitri John Ledkov launchpad at surgut.co.uk
Wed Mar 30 12:24:57 UTC 2016


Patch attached upstream
https://bugzilla.mindrot.org/show_bug.cgi?id=2559 see
https://bugzilla.mindrot.org/attachment.cgi?id=2801

As far as I understand there is no further actions for s390x port.

@OP this is a minor problem, and best addressed upstream, see upstream
bug report linked.

** Bug watch added: OpenSSH Portable Bugzilla #2559
   https://bugzilla.mindrot.org/show_bug.cgi?id=2559

** Also affects: openssh via
   https://bugzilla.mindrot.org/show_bug.cgi?id=2559
   Importance: Unknown
       Status: Unknown

** Changed in: openssh (Ubuntu)
   Importance: Low => Wishlist

-- 
You received this bug notification because you are a member of Ubuntu
Foundations Bugs, which is subscribed to openssh in Ubuntu.
https://bugs.launchpad.net/bugs/1528251

Title:
  WARNING: no suitable primes in /etc/ssh/primes

Status in portable OpenSSH:
  Unknown
Status in openssh package in Ubuntu:
  Triaged

Bug description:
  
  For instance when the KexAlgorithms option in sshd_config is set to include Diffie Hellman group exchange (e.g. diffie-hellman-group-exchange-sha256), and the /etc/ssh/moduli file is regenerated to include only 4096 bit primes, the ssh server may log the above warning message to /var/log/auth.log, probably because the ssh client trying to log in does not allow for the use of 4096 bit primes during the key exchange. The alleged problem is the reference to /etc/ssh/primes instead of /etc/ssh/moduli. It would appear that the file /etc/ssh/primes is neither used by ssh server, nor documented.

  I note that this error appears to have been reported in several places
  on the web in the past years, but to no avail (e.g.
  http://misc.openbsd.narkive.com/tZPNEoZk/no-suitable-primes)

  
  Release: Ubuntu 14.04.3 LTS
  Package: openssh-server, Version: 1:6.6p1-2ubuntu2.3

To manage notifications about this bug go to:
https://bugs.launchpad.net/openssh/+bug/1528251/+subscriptions



More information about the foundations-bugs mailing list