Re: Upcoming SSH Host Key Rotation for hg.mozilla.org

2016-04-06 Thread Philip Chee
On 05/04/2016 09:09, Philip Chee wrote: > On 04/04/2016 23:52, Gregory Szorc wrote: >> We also changed the SSH server config to only support the "modern" set of >> ciphers, MACs, algorithms, etc from >> https://wiki.mozilla.org/Security/Guidelines/OpenSSH#Modern. If you are >> running an old SSH

Re: Upcoming SSH Host Key Rotation for hg.mozilla.org

2016-04-06 Thread Philip Chee
On 05/04/2016 14:23, Onno Ekker wrote: > Op 5-4-2016 om 3:09 schreef Philip Chee: >> I'm using TortoiseHg whichh uses PuTTY and PLINK internally. I've >> deleted the mozilla host key and accepted the new one. >> >> Now I can't push to comm-central via TortoiseHg. I can't push directly >> via

Re: Upcoming SSH Host Key Rotation for hg.mozilla.org

2016-04-05 Thread Onno Ekker
Op 5-4-2016 om 3:09 schreef Philip Chee: > On 04/04/2016 23:52, Gregory Szorc wrote: >> We also changed the SSH server config to only support the "modern" set of >> ciphers, MACs, algorithms, etc from >> https://wiki.mozilla.org/Security/Guidelines/OpenSSH#Modern. If you are >> running an old SSH

Re: Upcoming SSH Host Key Rotation for hg.mozilla.org

2016-04-04 Thread Kendall Libby
As part of this, SSH DSA keys were no longer being accepted by the server. However, there is no easy way for most non-MoCo contributors to change their SSH keys, whereas MoCo users and communitiy members with LDAP accounts can (and should!) use login.mozilla.com to update their keys. So a bunch of

Re: Upcoming SSH Host Key Rotation for hg.mozilla.org

2016-04-04 Thread Gregory Szorc
We also changed the SSH server config to only support the "modern" set of ciphers, MACs, algorithms, etc from https://wiki.mozilla.org/Security/Guidelines/OpenSSH#Modern. If you are running an old SSH client, it may not be able to connect. If you encounter problems connecting, complain in #vcs

Re: Upcoming SSH Host Key Rotation for hg.mozilla.org

2016-04-04 Thread Gregory Szorc
This change was just made (we delayed because we didn't want to take extra risks on a Friday afternoon). A GPG signed document detailing the current keys is available at https://hg.mozilla.org/hgcustom/version-control-tools/raw-file/tip/docs/vcs-server-info.asc On 3/31/16 2:39 PM, Gregory Szorc