mirror of
https://github.com/sshnet/SSH.NET.git
synced 2026-09-10 17:25:51 +00:00
60f3cd803e
DSA is removed at compile time from OpenSSH 9.8 and higher.
That means we can no longer test it in our integration tests. It seems like a
good time to remove it. From the OpenSSH release notes:
DSA, as specified in the SSHv2 protocol, is inherently weak - being
limited to a 160 bit private key and use of the SHA1 digest. Its
estimated security level is only 80 bits symmetric equivalent.
OpenSSH has disabled DSA keys by default since 2015 but has retained
run-time optional support for them. DSA was the only mandatory-to-
implement algorithm in the SSHv2 RFCs, mostly because alternative
algorithms were encumbered by patents when the SSHv2 protocol was
specified.
This has not been the case for decades at this point and better
algorithms are well supported by all actively-maintained SSH
implementations. We do not consider the costs of maintaining DSA
in OpenSSH to be justified and hope that removing it from OpenSSH
can accelerate its wider deprecation in supporting cryptography
libraries.
147 lines
4.7 KiB
C#
147 lines
4.7 KiB
C#
using Renci.SshNet.Common;
|
|
using Renci.SshNet.IntegrationTests.Common;
|
|
using Renci.SshNet.Security;
|
|
using Renci.SshNet.TestTools.OpenSSH;
|
|
|
|
namespace Renci.SshNet.IntegrationTests
|
|
{
|
|
[TestClass]
|
|
public class HostKeyAlgorithmTests : IntegrationTestBase
|
|
{
|
|
private IConnectionInfoFactory _connectionInfoFactory;
|
|
private RemoteSshdConfig _remoteSshdConfig;
|
|
|
|
[TestInitialize]
|
|
public void SetUp()
|
|
{
|
|
_connectionInfoFactory = new LinuxVMConnectionFactory(SshServerHostName, SshServerPort);
|
|
_remoteSshdConfig = new RemoteSshd(new LinuxAdminConnectionFactory(SshServerHostName, SshServerPort)).OpenConfig();
|
|
}
|
|
|
|
[TestCleanup]
|
|
public void TearDown()
|
|
{
|
|
_remoteSshdConfig?.Reset();
|
|
}
|
|
|
|
[TestMethod]
|
|
public void SshRsa()
|
|
{
|
|
DoTest(HostKeyAlgorithm.SshRsa, HostKeyFile.Rsa);
|
|
}
|
|
|
|
[TestMethod]
|
|
public void SshRsaSha256()
|
|
{
|
|
DoTest(HostKeyAlgorithm.RsaSha2256, HostKeyFile.Rsa);
|
|
}
|
|
|
|
[TestMethod]
|
|
public void SshRsaSha512()
|
|
{
|
|
DoTest(HostKeyAlgorithm.RsaSha2512, HostKeyFile.Rsa);
|
|
}
|
|
|
|
[TestMethod]
|
|
public void SshEd25519()
|
|
{
|
|
DoTest(HostKeyAlgorithm.SshEd25519, HostKeyFile.Ed25519);
|
|
}
|
|
|
|
[TestMethod]
|
|
public void Ecdsa256()
|
|
{
|
|
DoTest(HostKeyAlgorithm.EcdsaSha2Nistp256, HostKeyFile.Ecdsa256);
|
|
}
|
|
|
|
[TestMethod]
|
|
public void Ecdsa384()
|
|
{
|
|
DoTest(HostKeyAlgorithm.EcdsaSha2Nistp384, HostKeyFile.Ecdsa384);
|
|
}
|
|
|
|
[TestMethod]
|
|
public void Ecdsa521()
|
|
{
|
|
DoTest(HostKeyAlgorithm.EcdsaSha2Nistp521, HostKeyFile.Ecdsa521);
|
|
}
|
|
|
|
[TestMethod]
|
|
public void SshRsaCertificate()
|
|
{
|
|
DoTest(HostKeyAlgorithm.SshRsaCertV01OpenSSH, HostCertificateFile.RsaCertRsa);
|
|
}
|
|
|
|
[TestMethod]
|
|
public void SshRsaSha256Certificate()
|
|
{
|
|
DoTest(HostKeyAlgorithm.RsaSha2256CertV01OpenSSH, HostCertificateFile.RsaCertRsa);
|
|
}
|
|
|
|
[TestMethod]
|
|
public void Ecdsa256Certificate()
|
|
{
|
|
DoTest(HostKeyAlgorithm.EcdsaSha2Nistp256CertV01OpenSSH, HostCertificateFile.Ecdsa256CertRsa);
|
|
}
|
|
|
|
[TestMethod]
|
|
public void Ecdsa384Certificate()
|
|
{
|
|
DoTest(HostKeyAlgorithm.EcdsaSha2Nistp384CertV01OpenSSH, HostCertificateFile.Ecdsa384CertEcdsa);
|
|
}
|
|
|
|
[TestMethod]
|
|
public void Ecdsa521Certificate()
|
|
{
|
|
DoTest(HostKeyAlgorithm.EcdsaSha2Nistp521CertV01OpenSSH, HostCertificateFile.Ecdsa521CertEd25519);
|
|
}
|
|
|
|
[TestMethod]
|
|
public void Ed25519Certificate()
|
|
{
|
|
DoTest(HostKeyAlgorithm.SshEd25519CertV01OpenSSH, HostCertificateFile.Ed25519CertEcdsa);
|
|
}
|
|
|
|
private void DoTest(HostKeyAlgorithm hostKeyAlgorithm, HostKeyFile hostKeyFile, HostCertificateFile hostCertificateFile = null)
|
|
{
|
|
_remoteSshdConfig.ClearHostKeyAlgorithms()
|
|
.AddHostKeyAlgorithm(hostKeyAlgorithm)
|
|
.ClearHostKeyFiles()
|
|
.AddHostKeyFile(hostKeyFile.FilePath)
|
|
.WithHostKeyCertificate(hostCertificateFile?.FilePath)
|
|
.Update()
|
|
.Restart();
|
|
|
|
HostKeyEventArgs hostKeyEventsArgs = null;
|
|
|
|
using (var client = new SshClient(_connectionInfoFactory.Create()))
|
|
{
|
|
client.HostKeyReceived += (sender, e) => hostKeyEventsArgs = e;
|
|
client.Connect();
|
|
client.Disconnect();
|
|
}
|
|
|
|
Assert.IsNotNull(hostKeyEventsArgs);
|
|
Assert.AreEqual(hostKeyAlgorithm.Name, hostKeyEventsArgs.HostKeyName);
|
|
Assert.AreEqual(hostKeyFile.KeyLength, hostKeyEventsArgs.KeyLength);
|
|
CollectionAssert.AreEqual(hostKeyFile.FingerPrint, hostKeyEventsArgs.FingerPrint);
|
|
|
|
if (hostCertificateFile is not null)
|
|
{
|
|
Assert.IsNotNull(hostKeyEventsArgs.Certificate);
|
|
Assert.AreEqual(Certificate.CertificateType.Host, hostKeyEventsArgs.Certificate.Type);
|
|
Assert.AreEqual(hostCertificateFile.CAFingerPrint, hostKeyEventsArgs.Certificate.CertificateAuthorityKeyFingerPrint);
|
|
}
|
|
else
|
|
{
|
|
Assert.IsNull(hostKeyEventsArgs.Certificate);
|
|
}
|
|
}
|
|
|
|
private void DoTest(HostKeyAlgorithm hostKeyAlgorithm, HostCertificateFile hostCertificateFile)
|
|
{
|
|
DoTest(hostKeyAlgorithm, hostCertificateFile.HostKeyFile, hostCertificateFile);
|
|
}
|
|
}
|
|
}
|