summaryrefslogtreecommitdiffstats
path: root/nixos/doc
diff options
context:
space:
mode:
authorJanne Heß <janne@hess.ooo>2021-11-09 21:56:43 +0100
committerGitHub <noreply@github.com>2021-11-09 21:56:43 +0100
commitedb295084a74415b60d8f9615500bff79d13b8b6 (patch)
tree9a2e265d01df6c9d713e9a474b3cfdeb8a835914 /nixos/doc
parente5ac2e1a52bbc9b7aaedd7ffc0b059471f20107e (diff)
parentfd567ad54ad706f0b636984224b46a5ddb8de81c (diff)
Merge pull request #145181 from helsinki-systems/release-notes/openssh
nixos/changelog: Mention OpenSSH upgrade
Diffstat (limited to 'nixos/doc')
-rw-r--r--nixos/doc/manual/from_md/release-notes/rl-2111.section.xml21
-rw-r--r--nixos/doc/manual/release-notes/rl-2111.section.md4
2 files changed, 25 insertions, 0 deletions
diff --git a/nixos/doc/manual/from_md/release-notes/rl-2111.section.xml b/nixos/doc/manual/from_md/release-notes/rl-2111.section.xml
index d0521f2db4df..93421493b76c 100644
--- a/nixos/doc/manual/from_md/release-notes/rl-2111.section.xml
+++ b/nixos/doc/manual/from_md/release-notes/rl-2111.section.xml
@@ -151,6 +151,27 @@
</listitem>
</itemizedlist>
</listitem>
+ <listitem>
+ <para>
+ OpenSSH was updated to version 8.8p1
+ </para>
+ <itemizedlist spacing="compact">
+ <listitem>
+ <para>
+ This breaks connections to old SSH daemons as ssh-rsa host
+ keys and ssh-rsa public keys that were signed with SHA-1
+ are disabled by default now
+ </para>
+ </listitem>
+ <listitem>
+ <para>
+ These can be re-enabled, see the
+ <link xlink:href="https://www.openssh.com/txt/release-8.8">OpenSSH
+ changelog</link> for details
+ </para>
+ </listitem>
+ </itemizedlist>
+ </listitem>
</itemizedlist>
</section>
<section xml:id="sec-release-21.11-new-services">
diff --git a/nixos/doc/manual/release-notes/rl-2111.section.md b/nixos/doc/manual/release-notes/rl-2111.section.md
index d957cf4ac0e0..febf4f97e2f5 100644
--- a/nixos/doc/manual/release-notes/rl-2111.section.md
+++ b/nixos/doc/manual/release-notes/rl-2111.section.md
@@ -46,6 +46,10 @@ In addition to numerous new and upgraded packages, this release has the followin
- building LXD images from configurations is now directly possible with just nixpkgs
- hydra is now building nixOS LXD images that can be used standalone with full nixos-rebuild support
+- OpenSSH was updated to version 8.8p1
+ - This breaks connections to old SSH daemons as ssh-rsa host keys and ssh-rsa public keys that were signed with SHA-1 are disabled by default now
+ - These can be re-enabled, see the [OpenSSH changelog](https://www.openssh.com/txt/release-8.8) for details
+
## New Services {#sec-release-21.11-new-services}
- [btrbk](https://digint.ch/btrbk/index.html), a backup tool for btrfs subvolumes, taking advantage of btrfs specific capabilities to create atomic snapshots and transfer them incrementally to your backup locations. Available as [services.btrbk](options.html#opt-services.brtbk.instances).