SSHFP observation

Mark Andrews marka at isc.org
Thu Jan 31 21:57:13 UTC 2019



> On 1 Feb 2019, at 7:34 am, Alan Clegg <alan at clegg.com> wrote:
> 
> On 1/31/19 2:16 PM, Alan Clegg wrote:
> 
>> Ok, fair point.  I'll bring it up with the BIND team.
>> 
>> If I don't return in 2 weeks, send in a search party.
> 
> After a bit of discussion:
> 
>   https://gitlab.isc.org/isc-projects/bind9/issues/852
> 
> has been re-opened.  I still think it's a junk fingerprint, but it does
> appear to me to be legal per-RFC.

Given type 1 is a SHA-1 fingerprint it isn’t legal.  Named just hasn’t added type to length to the parsing code.

No real SSHFP will be 1 octet long.

> AlanC
> _______________________________________________
> Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list
> 
> bind-users mailing list
> bind-users at lists.isc.org
> https://lists.isc.org/mailman/listinfo/bind-users

-- 
Mark Andrews, ISC
1 Seymour St., Dundas Valley, NSW 2117, Australia
PHONE: +61 2 9871 4742              INTERNET: marka at isc.org



More information about the bind-users mailing list