Skip to content

ssh: add ssh_pubkey_algorithms variable - #3928

Merged
ytti merged 1 commit into
ytti:masterfrom
fmcglinn:2875-ssh-pubkey-algorithms
Oct 9, 2026
Merged

ytti merged 1 commit into
ytti:masterfrom
fmcglinn:2875-ssh-pubkey-algorithms

Conversation

@fmcglinn

@fmcglinn fmcglinn commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

Pre-Request Checklist

  • Passes rubocop code analysis (try rubocop --auto-correct)
  • Tests added or adapted (try rake test) (no test: a spec could only assert the option reaches Net::SSH.start, which is Net::SSH's behaviour, not Oxidized's)
  • Model changes include a YAML simulation file
    and the expected output (no model change)
  • Changes are reflected in the documentation
  • User-visible changes appended to CHANGELOG.md

Description

Adds an ssh_pubkey_algorithms variable. It is passed to Net::SSH as pubkey_algorithms, in the same way that ssh_kex, ssh_encryption, ssh_host_key and ssh_hmac are passed today.

Why: Net::SSH (>= 7.1) signs with an RSA key using rsa-sha2-512/rsa-sha2-256 first. It falls back to ssh-rsa only after the server rejects those. Some devices don't reject them properly:

  • Huawei SmartAX MA5683T OLTs accept the key (SSH_MSG_USERAUTH_PK_OK), then close the connection when they receive the rsa-sha2-256 signature: disconnected: The connection is closed by SSH Server / Current FSM is SSH_Main_SSHProcess (2). Because it is a disconnect and not an auth failure, neither the ssh-rsa fallback nor the password auth method ever runs, and the node fails with no_connection. Running Net::SSH directly with pubkey_algorithms: %w[ssh-rsa] logs in fine. The SmartAX does not support ed25519 keys, so an RSA key with ssh-rsa is the only key-based option.
  • In Add the ability to configure pubkey_algorithms following Net:SSH 7.1.x upgrade #2875, a device logged a failed login on every backup before the fallback succeeded.

Until now, both cases needed a patch to the SSH input. With this change it is a per-model or per-node var:

models:
  smartax:
    vars:
      ssh_pubkey_algorithms: ssh-rsa

When the var is unset, behaviour is unchanged. The option only affects RSA keys; Net::SSH ignores it for other key types.

Changes:

  • lib/oxidized/input/sshbase.rb: map ssh_pubkey_algorithms (comma-separated) to pubkey_algorithms, and re-align the sibling ssh_* lines (whitespace only)
  • docs/Inputs.md: new "SSH public key algorithms" section, including a note that it only applies to RSA keys
  • CHANGELOG.md: entry under Unreleased / Added

Testing:

  • bundle exec rake test: 413 runs, 0 failures.
  • bundle exec rubocop: no offenses.
  • Manual: SmartAX MA5683T backs up with ssh_pubkey_algorithms: ssh-rsa; without it the node fails with no_connection.

Closes #2875

@ytti

ytti commented Oct 8, 2026

Copy link
Copy Markdown
Owner

Not sure the test does anything. You might want to ask the instance that the PubkeyAcceptedAlgorithms are as set as expected. However tests are not mandatory either, but I'm not sure there is value in no-op tests.

Net::SSH signs RSA keys with rsa-sha2-512/256 first and falls back to
ssh-rsa only when the server rejects them. Huawei SmartAX MA5683T OLTs
accept the key, then disconnect on the rsa-sha2-256 signature, so the
fallback never runs and the node fails. Other devices log a failed
login before the fallback succeeds (ytti#2875).

Map the ssh_pubkey_algorithms var to Net::SSH's pubkey_algorithms
option, the same way ssh_kex, ssh_encryption, ssh_host_key and ssh_hmac
are mapped.

Closes ytti#2875
@fmcglinn
fmcglinn force-pushed the 2875-ssh-pubkey-algorithms branch from 83ea69c to eac61e4 Compare October 8, 2026 21:02
@fmcglinn

fmcglinn commented Oct 8, 2026

Copy link
Copy Markdown
Contributor Author

Fair comments - at some point the tests become about testing Net::SSH rather which introduces fragility. Ive dropped the test and updated the PR.
Let me know if you have any other feedback, happy to adjust as needed :)

@ytti
ytti merged commit 2cac3f7 into ytti:master Oct 9, 2026
8 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Add the ability to configure pubkey_algorithms following Net:SSH 7.1.x upgrade

2 participants