| ︙ | | | ︙ | |
2830
2831
2832
2833
2834
2835
2836
2837
2838
2839
2840
2841
2842
2843
2844
2845
|
else
/* shouldn't happen */
bombout(("No supported ciphers found"));
crStop(0);
}
/* Warn about chosen cipher if necessary. */
if (warn)
askalg(ssh->frontend, "cipher", cipher_string);
}
switch (s->cipher_type) {
case SSH_CIPHER_3DES:
logevent("Using 3DES encryption");
break;
case SSH_CIPHER_DES:
|
|
>
>
>
|
2830
2831
2832
2833
2834
2835
2836
2837
2838
2839
2840
2841
2842
2843
2844
2845
2846
2847
2848
|
else
/* shouldn't happen */
bombout(("No supported ciphers found"));
crStop(0);
}
/* Warn about chosen cipher if necessary. */
if (warn) {
sk_set_frozen(ssh->s, 1);
askalg(ssh->frontend, "cipher", cipher_string);
sk_set_frozen(ssh->s, 0);
}
}
switch (s->cipher_type) {
case SSH_CIPHER_3DES:
logevent("Using 3DES encryption");
break;
case SSH_CIPHER_DES:
|
| ︙ | | | ︙ | |
4885
4886
4887
4888
4889
4890
4891
4892
4893
4894
4895
4896
4897
4898
4899
4900
4901
|
const struct ssh_kex *k = s->preferred_kex[i];
if (!k) {
s->warn = 1;
} else if (in_commasep_string(k->name, str, len)) {
ssh->kex = k;
}
if (ssh->kex) {
if (s->warn)
askalg(ssh->frontend, "key-exchange algorithm",
ssh->kex->name);
break;
}
}
if (!ssh->kex) {
bombout(("Couldn't agree a key exchange algorithm (available: %s)",
str ? str : "(null)"));
crStop(0);
|
|
>
>
>
|
4888
4889
4890
4891
4892
4893
4894
4895
4896
4897
4898
4899
4900
4901
4902
4903
4904
4905
4906
4907
|
const struct ssh_kex *k = s->preferred_kex[i];
if (!k) {
s->warn = 1;
} else if (in_commasep_string(k->name, str, len)) {
ssh->kex = k;
}
if (ssh->kex) {
if (s->warn) {
sk_set_frozen(ssh->s, 1);
askalg(ssh->frontend, "key-exchange algorithm",
ssh->kex->name);
sk_set_frozen(ssh->s, 0);
}
break;
}
}
if (!ssh->kex) {
bombout(("Couldn't agree a key exchange algorithm (available: %s)",
str ? str : "(null)"));
crStop(0);
|
| ︙ | | | ︙ | |
4918
4919
4920
4921
4922
4923
4924
4925
4926
4927
4928
4929
4930
4931
4932
4933
4934
|
if (in_commasep_string(c->list[j]->name, str, len)) {
s->cscipher_tobe = c->list[j];
break;
}
}
}
if (s->cscipher_tobe) {
if (s->warn)
askalg(ssh->frontend, "client-to-server cipher",
s->cscipher_tobe->name);
break;
}
}
if (!s->cscipher_tobe) {
bombout(("Couldn't agree a client-to-server cipher (available: %s)",
str ? str : "(null)"));
crStop(0);
|
|
>
>
>
|
4924
4925
4926
4927
4928
4929
4930
4931
4932
4933
4934
4935
4936
4937
4938
4939
4940
4941
4942
4943
|
if (in_commasep_string(c->list[j]->name, str, len)) {
s->cscipher_tobe = c->list[j];
break;
}
}
}
if (s->cscipher_tobe) {
if (s->warn) {
sk_set_frozen(ssh->s, 1);
askalg(ssh->frontend, "client-to-server cipher",
s->cscipher_tobe->name);
sk_set_frozen(ssh->s, 0);
}
break;
}
}
if (!s->cscipher_tobe) {
bombout(("Couldn't agree a client-to-server cipher (available: %s)",
str ? str : "(null)"));
crStop(0);
|
| ︙ | | | ︙ | |
4945
4946
4947
4948
4949
4950
4951
4952
4953
4954
4955
4956
4957
4958
4959
4960
4961
|
if (in_commasep_string(c->list[j]->name, str, len)) {
s->sccipher_tobe = c->list[j];
break;
}
}
}
if (s->sccipher_tobe) {
if (s->warn)
askalg(ssh->frontend, "server-to-client cipher",
s->sccipher_tobe->name);
break;
}
}
if (!s->sccipher_tobe) {
bombout(("Couldn't agree a server-to-client cipher (available: %s)",
str ? str : "(null)"));
crStop(0);
|
|
>
>
>
|
4954
4955
4956
4957
4958
4959
4960
4961
4962
4963
4964
4965
4966
4967
4968
4969
4970
4971
4972
4973
|
if (in_commasep_string(c->list[j]->name, str, len)) {
s->sccipher_tobe = c->list[j];
break;
}
}
}
if (s->sccipher_tobe) {
if (s->warn) {
sk_set_frozen(ssh->s, 1);
askalg(ssh->frontend, "server-to-client cipher",
s->sccipher_tobe->name);
sk_set_frozen(ssh->s, 0);
}
break;
}
}
if (!s->sccipher_tobe) {
bombout(("Couldn't agree a server-to-client cipher (available: %s)",
str ? str : "(null)"));
crStop(0);
|
| ︙ | | | ︙ | |
5104
5105
5106
5107
5108
5109
5110
5111
5112
5113
5114
5115
5116
5117
5118
5119
5120
|
/*
* Authenticate remote host: verify host key. (We've already
* checked the signature of the exchange hash.)
*/
s->keystr = ssh->hostkey->fmtkey(s->hkey);
s->fingerprint = ssh->hostkey->fingerprint(s->hkey);
verify_ssh_host_key(ssh->frontend,
ssh->savedhost, ssh->savedport, ssh->hostkey->keytype,
s->keystr, s->fingerprint);
if (!s->got_session_id) { /* don't bother logging this in rekeys */
logevent("Host key fingerprint is:");
logevent(s->fingerprint);
}
sfree(s->fingerprint);
sfree(s->keystr);
ssh->hostkey->freekey(s->hkey);
|
>
>
|
5116
5117
5118
5119
5120
5121
5122
5123
5124
5125
5126
5127
5128
5129
5130
5131
5132
5133
5134
|
/*
* Authenticate remote host: verify host key. (We've already
* checked the signature of the exchange hash.)
*/
s->keystr = ssh->hostkey->fmtkey(s->hkey);
s->fingerprint = ssh->hostkey->fingerprint(s->hkey);
sk_set_frozen(ssh->s, 1);
verify_ssh_host_key(ssh->frontend,
ssh->savedhost, ssh->savedport, ssh->hostkey->keytype,
s->keystr, s->fingerprint);
sk_set_frozen(ssh->s, 0);
if (!s->got_session_id) { /* don't bother logging this in rekeys */
logevent("Host key fingerprint is:");
logevent(s->fingerprint);
}
sfree(s->fingerprint);
sfree(s->keystr);
ssh->hostkey->freekey(s->hkey);
|
| ︙ | | | ︙ | |