From 4c9466aede9be8caef4698b0cd858292764c13ee Mon Sep 17 00:00:00 2001 From: dtucker Date: Sat, 24 Oct 2009 00:46:43 +0000 Subject: [PATCH] - djm@cvs.openbsd.org 2009/10/22 22:26:13 [authfile.c] switch from 3DES to AES-128 for encryption of passphrase-protected SSH protocol 2 private keys; ok several --- ChangeLog | 4 ++++ authfile.c | 4 ++-- 2 files changed, 6 insertions(+), 2 deletions(-) diff --git a/ChangeLog b/ChangeLog index 34351d47..5ec1345c 100644 --- a/ChangeLog +++ b/ChangeLog @@ -16,6 +16,10 @@ few remaining ".Tn UNIX" macros with ".Ux" ones. pointed out by ratchov@, thanks! ok jmc@ + - djm@cvs.openbsd.org 2009/10/22 22:26:13 + [authfile.c] + switch from 3DES to AES-128 for encryption of passphrase-protected + SSH protocol 2 private keys; ok several 20091011 - (dtucker) [configure.ac sftp-client.c] Remove the gyrations required for diff --git a/authfile.c b/authfile.c index 735c6478..22df6c64 100644 --- a/authfile.c +++ b/authfile.c @@ -1,4 +1,4 @@ -/* $OpenBSD: authfile.c,v 1.76 2006/08/03 03:34:41 deraadt Exp $ */ +/* $OpenBSD: authfile.c,v 1.77 2009/10/22 22:26:13 djm Exp $ */ /* * Author: Tatu Ylonen * Copyright (c) 1995 Tatu Ylonen , Espoo, Finland @@ -184,7 +184,7 @@ key_save_private_pem(Key *key, const char *filename, const char *_passphrase, int success = 0; int len = strlen(_passphrase); u_char *passphrase = (len > 0) ? (u_char *)_passphrase : NULL; - const EVP_CIPHER *cipher = (len > 0) ? EVP_des_ede3_cbc() : NULL; + const EVP_CIPHER *cipher = (len > 0) ? EVP_aes_128_cbc() : NULL; if (len > 0 && len <= 4) { error("passphrase too short: have %d bytes, need > 4", len); -- 2.45.2