[Bug 933480] Re: Picks hmac-md5 over hmac-sha1

Clint Byrum clint at fewbar.com
Sat Feb 18 23:46:42 UTC 2012

Hi Chris, thanks for taking the time to file this bug and help us make
Ubuntu better.

According to RFC 6151, this is not an urgent matter:


I do think that it is rather odd that hmac-md5 is still the default, but
the upstream openssh authors seems to find that acceptable, and so I
think we can also follow their lead. This is perhaps something to take
up with the OpenSSH developers on their mailing list.

Because it is not urgent and upstream has not seen fit to correct the
issue, I am marking this bug as Wishlist. It is definitely something to
consider, so I'm marking it as Confirmed.

Chris, it would be fantastic if you would forward this bug to the
OpenSSH mailing list to get the ball rolling on on a discussion. Once
you've done so, report back here the results of the discussion, and we
can mark this as Triaged (if there is a change to make) or perhaps close
it if upstream is not interested in changing the default.

** Changed in: openssh (Ubuntu)
   Importance: Undecided => Wishlist

** Changed in: openssh (Ubuntu)
       Status: New => Confirmed

You received this bug notification because you are a member of Ubuntu
Server Team, which is subscribed to openssh in Ubuntu.

  Picks hmac-md5 over hmac-sha1

To manage notifications about this bug go to:

More information about the Ubuntu-server-bugs mailing list