Re: SFTP clients and certificates

2011-01-24 Thread Walt Farrell
On Fri, 21 Jan 2011 14:17:42 -0500, Bruce Wheatley bwheat...@cds.ca wrote: So we have set up the SSH server on z/os with it's host key pair in a RACF certificate, z/os SSH client keys in certificates in RACF , but public keys for clients like WINSCP are in /$HOME/.ssh2/authorization. We would

SFTP clients and certificates

2011-01-21 Thread Bruce Wheatley
Question from our sysprog group: Is it true that most SFTP clients do not support certificates? TIA Bruce Wheatley Senior Information Security Analyst The Canadian Depository for Securities Limited 85 Richmond St. W. Toronto, ON M5H 2C9 (416) 365-8417

Re: SFTP clients and certificates

2011-01-21 Thread Kirk Wolf
Bruce, If you mean X.509 certificates, then no - the ssh2 spec does not include support for X.509 *per se*. The ssh2 spec does support public/private key authentication using RSA or DSA keys. *BUT* if you are using either IBM Ported Tools for z/OS OpenSSH 1.2 or Co:Z SFTP with IBM PT 1.1, you

Re: SFTP clients and certificates

2011-01-21 Thread Walt Farrell
On Fri, 21 Jan 2011 08:47:58 -0600, Bruce Wheatley bwheat...@cds.ca wrote: Question from our sysprog group: Is it true that most SFTP clients do not support certificates? I'm not sure they asked the question they really intended, so it would help to know why they are asking the question.

Re: SFTP clients and certificates

2011-01-21 Thread Bruce Wheatley
: SFTP clients and certificates On Fri, 21 Jan 2011 08:47:58 -0600, Bruce Wheatley bwheat...@cds.ca wrote: Question from our sysprog group: Is it true that most SFTP clients do not support certificates? I'm not sure they asked the question they really intended, so it would help to know why