Re-allow RSA host keys with SSH#24
Merged
Burnett01 merged 1 commit intoBurnett01:release/5.3from Mar 24, 2022
Merged
Conversation
RSA host keys are disabled by default on OpenSSH 8.8+ which is used by the base Alpine image, but many servers still use RSA host keys
Owner
|
Hello @jasongill thank you for your contribution. I‘m planning on implementing a CI pipeline that can test the current implementation against multiple SSH servers. Your change will also then tested against it and merged afterwards. The pipeline will be ready in a week. Thanks once again and expect my reply. Greetings :) |
Owner
|
Hey Jason I switched the base target to release/5.3 and will conduct the testing and release prep on that branch. It could take some time until I report back. |
Owner
|
Thanks for your contribution once again. |
Contributor
Author
|
great, thanks @Burnett01! looking forward to the new version. thank you for your hard work on this great Github Action! |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
RSA host keys are disabled by default on OpenSSH 8.8+ which is used by the base Alpine image, but many servers still use RSA host keys. See https://www.openssh.com/txt/release-8.8 under "Potentially-incompatible changes".
Obviously the ideal solution would be to upgrade OpenSSH on the destination servers, but that's not always feasible, so to allow this Github Action to work with older SSH servers, this pull requests adds the required ssh command line options to re-enable support for SSH host keys.
If you are using an up-to-date SSH server version, the option is ignored so this doesn't weaken security for anyone who is using a more secure server version.
Due to the way the entrypoint.sh script is written, I don't know that there's any better way to set these SSH command line options - you cannot override the "-e" option on the rsync command line using the "switches" variable as it gets overwritten after the switches are specified.