Can't connect with SFTP, no sha256 support

Bug #1461664 reported by WoodyEckelzone
16
This bug affects 3 people
Affects Status Importance Assigned to Milestone
krusader (Ubuntu)
Confirmed
Undecided
Unassigned

Bug Description

Recently Krusader can't connect to server over sftp.

`no match for method mac algo client->server`

AFAICS this is caused because new servers disabled sha1 for security reasons and Krusader (KIO) only supports hmac-sha1.

Krusader uses KIO -> libssh.

AFAICS the new libssh library supports the new sha256/sha512.

We need a fix/update badly, Krusader stopped connecting, and the method it uses seems to be insecure nowadays (AFAIK).

ProblemType: Bug
DistroRelease: Ubuntu 14.04
Package: krusader 1:2.4.0~beta3-2
ProcVersionSignature: Ubuntu 3.13.0-53.89-generic 3.13.11-ckt19
Uname: Linux 3.13.0-53-generic x86_64
ApportVersion: 2.14.1-0ubuntu3.11
Architecture: amd64
CurrentDesktop: Unity
Date: Wed Jun 3 21:29:36 2015
InstallationDate: Installed on 2013-04-26 (768 days ago)
InstallationMedia: Ubuntu 13.04 "Raring Ringtail" - Release amd64 (20130424)
SourcePackage: krusader
UpgradeStatus: Upgraded to trusty on 2014-04-24 (404 days ago)

Revision history for this message
WoodyEckelzone (bcr497) wrote :
Revision history for this message
WoodyEckelzone (bcr497) wrote :

A workaround seems to be using the fish:// method instead of sftp://

Revision history for this message
Launchpad Janitor (janitor) wrote :

Status changed to 'Confirmed' because the bug affects multiple users.

Changed in krusader (Ubuntu):
status: New → Confirmed
Revision history for this message
Benedykt 'Silmethule' Jaworski (silmethule) wrote :

Affects also krusader 1:2.4.0~beta3-2ubuntu1 from Ubuntu 15.04 vivid amd64.

Another (better? uses server-side sftp) workaround is to use sshfs to fuse-mount host’s filesystem and the browse in Krusader.

Revision history for this message
asdf (asdfg) wrote :

Ubuntu 16.04 LTS is also affected. It uses old libssh-0.6.3. SHA-2 support was added in libssh-0.7.0.

To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.