summaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorDarren Tucker <dtucker@zip.com.au>2009-10-24 11:46:43 +1100
committerDarren Tucker <dtucker@zip.com.au>2009-10-24 11:46:43 +1100
commitdfb9b716500f777563a8f6f36072210fea167530 (patch)
tree7bf46a6146d4d361529499b43eb1e0be26b54a17
parent98c9aec30e75ba890ed36227793e1e5ea6a23d45 (diff)
- djm@cvs.openbsd.org 2009/10/22 22:26:13
[authfile.c] switch from 3DES to AES-128 for encryption of passphrase-protected SSH protocol 2 private keys; ok several
-rw-r--r--ChangeLog4
-rw-r--r--authfile.c4
2 files changed, 6 insertions, 2 deletions
diff --git a/ChangeLog b/ChangeLog
index 34351d47..5ec1345c 100644
--- a/ChangeLog
+++ b/ChangeLog
@@ -16,6 +16,10 @@
few remaining ".Tn UNIX" macros with ".Ux" ones.
pointed out by ratchov@, thanks!
ok jmc@
+ - djm@cvs.openbsd.org 2009/10/22 22:26:13
+ [authfile.c]
+ switch from 3DES to AES-128 for encryption of passphrase-protected
+ SSH protocol 2 private keys; ok several
20091011
- (dtucker) [configure.ac sftp-client.c] Remove the gyrations required for
diff --git a/authfile.c b/authfile.c
index 735c6478..22df6c64 100644
--- a/authfile.c
+++ b/authfile.c
@@ -1,4 +1,4 @@
-/* $OpenBSD: authfile.c,v 1.76 2006/08/03 03:34:41 deraadt Exp $ */
+/* $OpenBSD: authfile.c,v 1.77 2009/10/22 22:26:13 djm Exp $ */
/*
* Author: Tatu Ylonen <ylo@cs.hut.fi>
* Copyright (c) 1995 Tatu Ylonen <ylo@cs.hut.fi>, Espoo, Finland
@@ -184,7 +184,7 @@ key_save_private_pem(Key *key, const char *filename, const char *_passphrase,
int success = 0;
int len = strlen(_passphrase);
u_char *passphrase = (len > 0) ? (u_char *)_passphrase : NULL;
- const EVP_CIPHER *cipher = (len > 0) ? EVP_des_ede3_cbc() : NULL;
+ const EVP_CIPHER *cipher = (len > 0) ? EVP_aes_128_cbc() : NULL;
if (len > 0 && len <= 4) {
error("passphrase too short: have %d bytes, need > 4", len);