diff options
author | Anselm Kruis <a.kruis@science-computing.de> | 2017-08-01 13:18:19 +0200 |
---|---|---|
committer | Anselm Kruis <a.kruis@science-computing.de> | 2017-08-04 16:45:52 +0200 |
commit | 1b2697b3418cdf8e76831b7c02da848123d3f606 (patch) | |
tree | 662de0c403a573f9688ef0fa8527b221b4217c46 /sites/www/changelog.rst | |
parent | 853a37f5a47ce1b0a9719e8e201e0ee48207631e (diff) |
SSHClient: fix the host key test
Skip the host key check only, if the transport actually used
gssapi-keyex. Add tests for the missing-host-key RejectPolicy.
Before this change, a man-in-the-middle attack on the paramiko ssh
client with gss_kex=True was possible by having a server that does not
support gssapi-keyex and gives any or no host key.
Diffstat (limited to 'sites/www/changelog.rst')
0 files changed, 0 insertions, 0 deletions