[Touch-packages] [Bug 1445620] [NEW] Generate curve25519 keys by default - target 15.10

2015-04-17 Thread Joey Stanford
Public bug reported: For security and compatibility reasons, the Ubuntu Distro should generate curve25519 keys by default with a target 15.10 (or earlier). ** Affects: openssh (Ubuntu) Importance: Undecided Status: New -- You received this bug notification because you are a

[Touch-packages] [Bug 1445624] [NEW] Change SSH defaults to non-SHA-1 by 16.04

2015-04-17 Thread Joey Stanford
Public bug reported: For Security reasons, the Ubuntu Distro should change SSH defaults to use non-SHA-1 by 16.04. That is, to default to SHA2 and, ideally, not permit SHA1. This may break bzr+ssh on LP if done before https://bugs.launchpad.net/launchpad/+bug/1445619 ** Affects: openssh

[Touch-packages] [Bug 1445625] [NEW] Change the default RSA generation from 2048 to 4096

2015-04-17 Thread Joey Stanford
Public bug reported: For security purposes, the Ubuntu Distro should consider changing the default RSA generation from 2048 to 4096. This is a could be a somewhat disruptive change (e.g. accessing older Cisco devices may not work). We should still try to consider this and target this for 16.04.