haussli / draft-dahm-opsawg-tacacs-security

IETF draft for new tacacs+ security features
1 stars 1 forks source link

What key types are supported by the RFC4716 SSH pubkey format #52

Open haussli opened 1 year ago

haussli commented 1 year ago

There is a claim that the RFC4716 SSH pubkey format only supports RSA keys. Is this true?

haussli commented 1 year ago

Douglas said on today's call that he reviewed the RFC and did not believe that it would not support other key types.

MarcJHuber commented 1 year ago

Unfortunately, this isn't obvious at first glance (mainly due to authorized_keys2 file format choices): For ssh2, the key type is embedded in the actual ssh2 key (first four bytes: key type length, followed by the key type in plain ASCII).