Mercurial > dropbear
view dropbearconvert.1 @ 1715:3974f087d9c0
Disallow leading lines before the ident for server (#102)
Per RFC4253 4.2 clients must be able to process other lines of data
before the version string, server behavior is not defined neither
with MUST/SHOULD nor with MAY.
If server process up to 50 lines too - it may cause too long hanging
session with invalid/evil client that consume host resources and
potentially may lead to DDoS on poor embedded boxes.
Let's require first line from client to be version string and fail
early if it's not - matches both RFC and real OpenSSH behavior.
author | Vladislav Grishenko <themiron@users.noreply.github.com> |
---|---|
date | Mon, 15 Jun 2020 18:22:18 +0500 |
parents | 80cacacfec23 |
children | 863f31b4cf3c |
line wrap: on
line source
.TH dropbearconvert 1 .SH NAME dropbearconvert \- convert between Dropbear and OpenSSH private key formats .SH SYNOPSIS .B dropbearconvert .I input_type .I output_type .I input_file .I output_file .SH DESCRIPTION .B Dropbear and .B OpenSSH SSH implementations have different private key formats. .B dropbearconvert can convert between the two. .P Dropbear uses the same SSH public key format as OpenSSH, it can be extracted from a private key by using .B dropbearkey \-y .P Encrypted private keys are not supported, use ssh-keygen(1) to decrypt them first. .SH ARGUMENTS .TP .I input_type Either .I dropbear or .I openssh .TP .I output_type Either .I dropbear or .I openssh .TP .I input_file An existing Dropbear or OpenSSH private key file .TP .I output_file The path to write the converted private key file. For client authentication ~/.ssh/id_dropbear is loaded by default .SH EXAMPLE # dropbearconvert openssh dropbear ~/.ssh/id_rsa ~/.ssh/id_dropbear .SH AUTHOR Matt Johnston ([email protected]). .SH SEE ALSO dropbearkey(1), ssh-keygen(1) .P https://matt.ucc.asn.au/dropbear/dropbear.html