Repository navigation
ssh: add ssh_pubkey_algorithms variable - #3928
Merged
Merged
Conversation
Owner
|
Not sure the test does anything. You might want to ask the instance that the PubkeyAcceptedAlgorithms are as set as expected. However tests are not mandatory either, but I'm not sure there is value in no-op tests. |
Net::SSH signs RSA keys with rsa-sha2-512/256 first and falls back to ssh-rsa only when the server rejects them. Huawei SmartAX MA5683T OLTs accept the key, then disconnect on the rsa-sha2-256 signature, so the fallback never runs and the node fails. Other devices log a failed login before the fallback succeeds (ytti#2875). Map the ssh_pubkey_algorithms var to Net::SSH's pubkey_algorithms option, the same way ssh_kex, ssh_encryption, ssh_host_key and ssh_hmac are mapped. Closes ytti#2875
fmcglinn
force-pushed
the
2875-ssh-pubkey-algorithms
branch
from
October 8, 2026 21:02
83ea69c to
eac61e4
Compare
Contributor
Author
|
Fair comments - at some point the tests become about testing Net::SSH rather which introduces fragility. Ive dropped the test and updated the PR. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Pre-Request Checklist
rubocop --auto-correct)rake test) (no test: a spec could only assert the option reachesNet::SSH.start, which is Net::SSH's behaviour, not Oxidized's)and the expected output (no model change)
Description
Adds an
ssh_pubkey_algorithmsvariable. It is passed to Net::SSH aspubkey_algorithms, in the same way thatssh_kex,ssh_encryption,ssh_host_keyandssh_hmacare passed today.Why: Net::SSH (>= 7.1) signs with an RSA key using
rsa-sha2-512/rsa-sha2-256first. It falls back tossh-rsaonly after the server rejects those. Some devices don't reject them properly:SSH_MSG_USERAUTH_PK_OK), then close the connection when they receive thersa-sha2-256signature:disconnected: The connection is closed by SSH Server / Current FSM is SSH_Main_SSHProcess (2). Because it is a disconnect and not an auth failure, neither thessh-rsafallback nor thepasswordauth method ever runs, and the node fails withno_connection. Running Net::SSH directly withpubkey_algorithms: %w[ssh-rsa]logs in fine. The SmartAX does not support ed25519 keys, so an RSA key withssh-rsais the only key-based option.pubkey_algorithmsfollowing Net:SSH 7.1.x upgrade #2875, a device logged a failed login on every backup before the fallback succeeded.Until now, both cases needed a patch to the SSH input. With this change it is a per-model or per-node var:
When the var is unset, behaviour is unchanged. The option only affects RSA keys; Net::SSH ignores it for other key types.
Changes:
lib/oxidized/input/sshbase.rb: mapssh_pubkey_algorithms(comma-separated) topubkey_algorithms, and re-align the siblingssh_*lines (whitespace only)docs/Inputs.md: new "SSH public key algorithms" section, including a note that it only applies to RSA keysCHANGELOG.md: entry under Unreleased / AddedTesting:
bundle exec rake test: 413 runs, 0 failures.bundle exec rubocop: no offenses.ssh_pubkey_algorithms: ssh-rsa; without it the node fails withno_connection.Closes #2875