Dmitry Belyavskiy 9dff9c
diff -up openssh-8.6p1/ssh_config.5.crypto-policies openssh-8.6p1/ssh_config.5
Dmitry Belyavskiy 9dff9c
--- openssh-8.6p1/ssh_config.5.crypto-policies	2021-04-19 15:18:32.071920379 +0200
Dmitry Belyavskiy 9dff9c
+++ openssh-8.6p1/ssh_config.5	2021-04-19 15:21:18.400179265 +0200
Dmitry Belyavskiy 9dff9c
@@ -368,15 +368,13 @@ or
Petr Šabata 81d24c
 .Qq *.c.example.com
Petr Šabata 81d24c
 domains.
Petr Šabata 81d24c
 .It Cm CASignatureAlgorithms
Petr Šabata 81d24c
+The default is handled system-wide by
Petr Šabata 81d24c
+.Xr crypto-policies 7 .
Petr Šabata 81d24c
+To see the defaults and how to modify this default, see manual page
Petr Šabata 81d24c
+.Xr update-crypto-policies 8 .
Petr Šabata 81d24c
+.Pp
Petr Šabata 81d24c
 Specifies which algorithms are allowed for signing of certificates
Petr Šabata 81d24c
 by certificate authorities (CAs).
Petr Šabata 81d24c
-The default is:
Petr Šabata 81d24c
-.Bd -literal -offset indent
Dmitry Belyavskiy 9dff9c
-ssh-ed25519,ecdsa-sha2-nistp256,ecdsa-sha2-nistp384,ecdsa-sha2-nistp521,
Dmitry Belyavskiy 9dff9c
-sk-ssh-ed25519@openssh.com,sk-ecdsa-sha2-nistp256@openssh.com,
Dmitry Belyavskiy 9dff9c
-rsa-sha2-512,rsa-sha2-256
Petr Šabata 81d24c
-.Ed
Petr Šabata 81d24c
-.Pp
Petr Šabata 81d24c
 .Xr ssh 1
Petr Šabata 81d24c
 will not accept host certificates signed using algorithms other than those
Petr Šabata 81d24c
 specified.
Dmitry Belyavskiy 9dff9c
@@ -436,20 +434,25 @@ If the option is set to
DistroBaker d029bb
 (the default),
Petr Šabata 81d24c
 the check will not be executed.
Petr Šabata 81d24c
 .It Cm Ciphers
Petr Šabata 81d24c
+The default is handled system-wide by
Petr Šabata 81d24c
+.Xr crypto-policies 7 .
Petr Šabata 81d24c
+To see the defaults and how to modify this default, see manual page
Petr Šabata 81d24c
+.Xr update-crypto-policies 8 .
Petr Šabata 81d24c
+.Pp
Petr Šabata 81d24c
 Specifies the ciphers allowed and their order of preference.
Petr Šabata 81d24c
 Multiple ciphers must be comma-separated.
Petr Šabata 81d24c
 If the specified list begins with a
Petr Šabata 81d24c
 .Sq +
Petr Šabata 81d24c
-character, then the specified ciphers will be appended to the default set
Petr Šabata 81d24c
-instead of replacing them.
Petr Šabata 81d24c
+character, then the specified ciphers will be appended to the built-in
Petr Šabata 81d24c
+openssh default set instead of replacing them.
Petr Šabata 81d24c
 If the specified list begins with a
Petr Šabata 81d24c
 .Sq -
Petr Šabata 81d24c
 character, then the specified ciphers (including wildcards) will be removed
Petr Šabata 81d24c
-from the default set instead of replacing them.
Petr Šabata 81d24c
+from the built-in openssh default set instead of replacing them.
Petr Šabata 81d24c
 If the specified list begins with a
Petr Šabata 81d24c
 .Sq ^
Petr Šabata 81d24c
 character, then the specified ciphers will be placed at the head of the
Petr Šabata 81d24c
-default set.
Petr Šabata 81d24c
+built-in openssh default set.
Petr Šabata 81d24c
 .Pp
Petr Šabata 81d24c
 The supported ciphers are:
Petr Šabata 81d24c
 .Bd -literal -offset indent
Dmitry Belyavskiy 9dff9c
@@ -465,13 +468,6 @@ aes256-gcm@openssh.com
Petr Šabata 81d24c
 chacha20-poly1305@openssh.com
Petr Šabata 81d24c
 .Ed
Petr Šabata 81d24c
 .Pp
Petr Šabata 81d24c
-The default is:
Petr Šabata 81d24c
-.Bd -literal -offset indent
Petr Šabata 81d24c
-chacha20-poly1305@openssh.com,
Petr Šabata 81d24c
-aes128-ctr,aes192-ctr,aes256-ctr,
Petr Šabata 81d24c
-aes128-gcm@openssh.com,aes256-gcm@openssh.com
Petr Šabata 81d24c
-.Ed
Petr Šabata 81d24c
-.Pp
Petr Šabata 81d24c
 The list of available ciphers may also be obtained using
Petr Šabata 81d24c
 .Qq ssh -Q cipher .
Petr Šabata 81d24c
 .It Cm ClearAllForwardings
Dmitry Belyavskiy 9dff9c
@@ -826,6 +822,11 @@ command line will be passed untouched to
Petr Šabata 81d24c
 The default is
Petr Šabata 81d24c
 .Dq no .
Petr Šabata 81d24c
 .It Cm GSSAPIKexAlgorithms
Petr Šabata 81d24c
+The default is handled system-wide by
Petr Šabata 81d24c
+.Xr crypto-policies 7 .
Petr Šabata 81d24c
+To see the defaults and how to modify this default, see manual page
Petr Šabata 81d24c
+.Xr update-crypto-policies 8 .
Petr Šabata 81d24c
+.Pp
Petr Šabata 81d24c
 The list of key exchange algorithms that are offered for GSSAPI
Petr Šabata 81d24c
 key exchange. Possible values are
Petr Šabata 81d24c
 .Bd -literal -offset 3n
Dmitry Belyavskiy 9dff9c
@@ -838,10 +839,8 @@ gss-nistp256-sha256-,
Petr Šabata 81d24c
 gss-curve25519-sha256-
Petr Šabata 81d24c
 .Ed
Petr Šabata 81d24c
 .Pp
Petr Šabata 81d24c
-The default is
Petr Šabata 81d24c
-.Dq gss-group14-sha256-,gss-group16-sha512-,gss-nistp256-sha256-,
Petr Šabata 81d24c
-gss-curve25519-sha256-,gss-group14-sha1-,gss-gex-sha1- .
Petr Šabata 81d24c
 This option only applies to connections using GSSAPI.
Petr Šabata 81d24c
+.Pp
Petr Šabata 81d24c
 .It Cm HashKnownHosts
Petr Šabata 81d24c
 Indicates that
Petr Šabata 81d24c
 .Xr ssh 1
Dmitry Belyavskiy 9dff9c
@@ -1169,29 +1168,25 @@ it may be zero or more of:
Petr Šabata 81d24c
 and
Petr Šabata 81d24c
 .Cm pam .
Petr Šabata 81d24c
 .It Cm KexAlgorithms
Petr Šabata 81d24c
+The default is handled system-wide by
Petr Šabata 81d24c
+.Xr crypto-policies 7 .
Petr Šabata 81d24c
+To see the defaults and how to modify this default, see manual page
Petr Šabata 81d24c
+.Xr update-crypto-policies 8 .
Petr Šabata 81d24c
+.Pp
Petr Šabata 81d24c
 Specifies the available KEX (Key Exchange) algorithms.
Petr Šabata 81d24c
 Multiple algorithms must be comma-separated.
Petr Šabata 81d24c
 If the specified list begins with a
Petr Šabata 81d24c
 .Sq +
Petr Šabata 81d24c
-character, then the specified methods will be appended to the default set
Petr Šabata 81d24c
-instead of replacing them.
Petr Šabata 81d24c
+character, then the specified methods will be appended to the built-in
Petr Šabata 81d24c
+openssh default set instead of replacing them.
Petr Šabata 81d24c
 If the specified list begins with a
Petr Šabata 81d24c
 .Sq -
Petr Šabata 81d24c
 character, then the specified methods (including wildcards) will be removed
Petr Šabata 81d24c
-from the default set instead of replacing them.
Petr Šabata 81d24c
+from the built-in openssh default set instead of replacing them.
Petr Šabata 81d24c
 If the specified list begins with a
Petr Šabata 81d24c
 .Sq ^
Petr Šabata 81d24c
 character, then the specified methods will be placed at the head of the
Petr Šabata 81d24c
-default set.
Petr Šabata 81d24c
-The default is:
Petr Šabata 81d24c
-.Bd -literal -offset indent
Petr Šabata 81d24c
-curve25519-sha256,curve25519-sha256@libssh.org,
Petr Šabata 81d24c
-ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,
Petr Šabata 81d24c
-diffie-hellman-group-exchange-sha256,
Petr Šabata 81d24c
-diffie-hellman-group16-sha512,
Petr Šabata 81d24c
-diffie-hellman-group18-sha512,
Petr Šabata 81d24c
-diffie-hellman-group14-sha256
Petr Šabata 81d24c
-.Ed
Petr Šabata 81d24c
+built-in openssh default set.
Petr Šabata 81d24c
 .Pp
Petr Šabata 81d24c
 The list of available key exchange algorithms may also be obtained using
Petr Šabata 81d24c
 .Qq ssh -Q kex .
Dmitry Belyavskiy 9dff9c
@@ -1301,37 +1296,33 @@ function, and all code in the
DistroBaker d029bb
 file.
DistroBaker d029bb
 This option is intended for debugging and no overrides are enabled by default.
Petr Šabata 81d24c
 .It Cm MACs
Petr Šabata 81d24c
+The default is handled system-wide by
Petr Šabata 81d24c
+.Xr crypto-policies 7 .
Petr Šabata 81d24c
+To see the defaults and how to modify this default, see manual page
Petr Šabata 81d24c
+.Xr update-crypto-policies 8 .
Petr Šabata 81d24c
+.Pp
Petr Šabata 81d24c
 Specifies the MAC (message authentication code) algorithms
Petr Šabata 81d24c
 in order of preference.
Petr Šabata 81d24c
 The MAC algorithm is used for data integrity protection.
Petr Šabata 81d24c
 Multiple algorithms must be comma-separated.
Petr Šabata 81d24c
 If the specified list begins with a
Petr Šabata 81d24c
 .Sq +
Petr Šabata 81d24c
-character, then the specified algorithms will be appended to the default set
Petr Šabata 81d24c
-instead of replacing them.
Petr Šabata 81d24c
+character, then the specified algorithms will be appended to the built-in
Petr Šabata 81d24c
+openssh default set instead of replacing them.
Petr Šabata 81d24c
 If the specified list begins with a
Petr Šabata 81d24c
 .Sq -
Petr Šabata 81d24c
 character, then the specified algorithms (including wildcards) will be removed
Petr Šabata 81d24c
-from the default set instead of replacing them.
Petr Šabata 81d24c
+from the built-in openssh default set instead of replacing them.
Petr Šabata 81d24c
 If the specified list begins with a
Petr Šabata 81d24c
 .Sq ^
Petr Šabata 81d24c
 character, then the specified algorithms will be placed at the head of the
Petr Šabata 81d24c
-default set.
Petr Šabata 81d24c
+built-in openssh default set.
Petr Šabata 81d24c
 .Pp
Petr Šabata 81d24c
 The algorithms that contain
Petr Šabata 81d24c
 .Qq -etm
Petr Šabata 81d24c
 calculate the MAC after encryption (encrypt-then-mac).
Petr Šabata 81d24c
 These are considered safer and their use recommended.
Petr Šabata 81d24c
 .Pp
Petr Šabata 81d24c
-The default is:
Petr Šabata 81d24c
-.Bd -literal -offset indent
Petr Šabata 81d24c
-umac-64-etm@openssh.com,umac-128-etm@openssh.com,
Petr Šabata 81d24c
-hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,
Petr Šabata 81d24c
-hmac-sha1-etm@openssh.com,
Petr Šabata 81d24c
-umac-64@openssh.com,umac-128@openssh.com,
Petr Šabata 81d24c
-hmac-sha2-256,hmac-sha2-512,hmac-sha1
Petr Šabata 81d24c
-.Ed
Petr Šabata 81d24c
-.Pp
Petr Šabata 81d24c
 The list of available MAC algorithms may also be obtained using
Petr Šabata 81d24c
 .Qq ssh -Q mac .
Petr Šabata 81d24c
 .It Cm NoHostAuthenticationForLocalhost
Dmitry Belyavskiy 9dff9c
@@ -1503,37 +1494,25 @@ instead of continuing to execute and pas
Petr Šabata 81d24c
 The default is
Petr Šabata 81d24c
 .Cm no .
DistroBaker d029bb
 .It Cm PubkeyAcceptedAlgorithms
Petr Šabata 81d24c
+The default is handled system-wide by
Petr Šabata 81d24c
+.Xr crypto-policies 7 .
Petr Šabata 81d24c
+To see the defaults and how to modify this default, see manual page
Petr Šabata 81d24c
+.Xr update-crypto-policies 8 .
Petr Šabata 81d24c
+.Pp
DistroBaker d029bb
 Specifies the signature algorithms that will be used for public key
DistroBaker d029bb
 authentication as a comma-separated list of patterns.
Petr Šabata 81d24c
 If the specified list begins with a
Petr Šabata 81d24c
 .Sq +
DistroBaker d029bb
-character, then the algorithms after it will be appended to the default
Petr Šabata 81d24c
-instead of replacing it.
DistroBaker d029bb
+character, then the algorithms after it will be appended to the built-in
Petr Šabata 81d24c
+openssh default instead of replacing it.
Petr Šabata 81d24c
 If the specified list begins with a
Petr Šabata 81d24c
 .Sq -
DistroBaker d029bb
 character, then the specified algorithms (including wildcards) will be removed
Petr Šabata 81d24c
-from the default set instead of replacing them.
Petr Šabata 81d24c
+from the built-in openssh default set instead of replacing them.
Petr Šabata 81d24c
 If the specified list begins with a
Petr Šabata 81d24c
 .Sq ^
DistroBaker d029bb
 character, then the specified algorithms will be placed at the head of the
Petr Šabata 81d24c
-default set.
Petr Šabata 81d24c
-The default for this option is:
Petr Šabata 81d24c
-.Bd -literal -offset 3n
DistroBaker d029bb
-ssh-ed25519-cert-v01@openssh.com,
Petr Šabata 81d24c
-ecdsa-sha2-nistp256-cert-v01@openssh.com,
Petr Šabata 81d24c
-ecdsa-sha2-nistp384-cert-v01@openssh.com,
Petr Šabata 81d24c
-ecdsa-sha2-nistp521-cert-v01@openssh.com,
Petr Šabata 81d24c
-sk-ssh-ed25519-cert-v01@openssh.com,
DistroBaker d029bb
-sk-ecdsa-sha2-nistp256-cert-v01@openssh.com,
Petr Šabata 81d24c
-rsa-sha2-512-cert-v01@openssh.com,
Petr Šabata 81d24c
-rsa-sha2-256-cert-v01@openssh.com,
Petr Šabata 81d24c
-ssh-rsa-cert-v01@openssh.com,
DistroBaker d029bb
-ssh-ed25519,
Petr Šabata 81d24c
-ecdsa-sha2-nistp256,ecdsa-sha2-nistp384,ecdsa-sha2-nistp521,
DistroBaker d029bb
-sk-ssh-ed25519@openssh.com,
Petr Šabata 81d24c
-sk-ecdsa-sha2-nistp256@openssh.com,
Petr Šabata 81d24c
-rsa-sha2-512,rsa-sha2-256,ssh-rsa
Petr Šabata 81d24c
-.Ed
Petr Šabata 81d24c
+built-in openssh default set.
Petr Šabata 81d24c
 .Pp
DistroBaker d029bb
 The list of available signature algorithms may also be obtained using
DistroBaker d029bb
 .Qq ssh -Q PubkeyAcceptedAlgorithms .
Dmitry Belyavskiy 9dff9c
diff -up openssh-8.6p1/sshd_config.5.crypto-policies openssh-8.6p1/sshd_config.5
Dmitry Belyavskiy 9dff9c
--- openssh-8.6p1/sshd_config.5.crypto-policies	2021-04-19 15:18:32.062920311 +0200
Dmitry Belyavskiy 9dff9c
+++ openssh-8.6p1/sshd_config.5	2021-04-19 15:20:42.591908243 +0200
Dmitry Belyavskiy 9dff9c
@@ -373,15 +373,13 @@ If the argument is
Petr Šabata 81d24c
 then no banner is displayed.
Petr Šabata 81d24c
 By default, no banner is displayed.
Petr Šabata 81d24c
 .It Cm CASignatureAlgorithms
Petr Šabata 81d24c
+The default is handled system-wide by
Petr Šabata 81d24c
+.Xr crypto-policies 7 .
Petr Šabata 81d24c
+To see the defaults and how to modify this default, see manual page
Petr Šabata 81d24c
+.Xr update-crypto-policies 8 .
Petr Šabata 81d24c
+.Pp
Petr Šabata 81d24c
 Specifies which algorithms are allowed for signing of certificates
Petr Šabata 81d24c
 by certificate authorities (CAs).
Petr Šabata 81d24c
-The default is:
Petr Šabata 81d24c
-.Bd -literal -offset indent
Dmitry Belyavskiy 9dff9c
-ssh-ed25519,ecdsa-sha2-nistp256,ecdsa-sha2-nistp384,ecdsa-sha2-nistp521,
Dmitry Belyavskiy 9dff9c
-sk-ssh-ed25519@openssh.com,sk-ecdsa-sha2-nistp256@openssh.com,
Dmitry Belyavskiy 9dff9c
-rsa-sha2-512,rsa-sha2-256
Petr Šabata 81d24c
-.Ed
Petr Šabata 81d24c
-.Pp
Petr Šabata 81d24c
 Certificates signed using other algorithms will not be accepted for
Petr Šabata 81d24c
 public key or host-based authentication.
Petr Šabata 81d24c
 .It Cm ChallengeResponseAuthentication
Dmitry Belyavskiy 9dff9c
@@ -445,20 +443,25 @@ The default is
Petr Šabata 81d24c
 indicating not to
Petr Šabata 81d24c
 .Xr chroot 2 .
Petr Šabata 81d24c
 .It Cm Ciphers
Petr Šabata 81d24c
+The default is handled system-wide by
Petr Šabata 81d24c
+.Xr crypto-policies 7 .
Petr Šabata 81d24c
+To see the defaults and how to modify this default, see manual page
Petr Šabata 81d24c
+.Xr update-crypto-policies 8 .
Petr Šabata 81d24c
+.Pp
Petr Šabata 81d24c
 Specifies the ciphers allowed.
Petr Šabata 81d24c
 Multiple ciphers must be comma-separated.
Petr Šabata 81d24c
 If the specified list begins with a
Petr Šabata 81d24c
 .Sq +
Petr Šabata 81d24c
-character, then the specified ciphers will be appended to the default set
Petr Šabata 81d24c
-instead of replacing them.
Petr Šabata 81d24c
+character, then the specified ciphers will be appended to the built-in
Petr Šabata 81d24c
+openssh default set instead of replacing them.
Petr Šabata 81d24c
 If the specified list begins with a
Petr Šabata 81d24c
 .Sq -
Petr Šabata 81d24c
 character, then the specified ciphers (including wildcards) will be removed
Petr Šabata 81d24c
-from the default set instead of replacing them.
Petr Šabata 81d24c
+from the built-in openssh default set instead of replacing them.
Petr Šabata 81d24c
 If the specified list begins with a
Petr Šabata 81d24c
 .Sq ^
Petr Šabata 81d24c
 character, then the specified ciphers will be placed at the head of the
Petr Šabata 81d24c
-default set.
Petr Šabata 81d24c
+built-in openssh default set.
Petr Šabata 81d24c
 .Pp
Petr Šabata 81d24c
 The supported ciphers are:
Petr Šabata 81d24c
 .Pp
Dmitry Belyavskiy 9dff9c
@@ -485,13 +488,6 @@ aes256-gcm@openssh.com
Petr Šabata 81d24c
 chacha20-poly1305@openssh.com
Petr Šabata 81d24c
 .El
Petr Šabata 81d24c
 .Pp
Petr Šabata 81d24c
-The default is:
Petr Šabata 81d24c
-.Bd -literal -offset indent
Petr Šabata 81d24c
-chacha20-poly1305@openssh.com,
Petr Šabata 81d24c
-aes128-ctr,aes192-ctr,aes256-ctr,
Petr Šabata 81d24c
-aes128-gcm@openssh.com,aes256-gcm@openssh.com
Petr Šabata 81d24c
-.Ed
Petr Šabata 81d24c
-.Pp
Petr Šabata 81d24c
 The list of available ciphers may also be obtained using
Petr Šabata 81d24c
 .Qq ssh -Q cipher .
Petr Šabata 81d24c
 .It Cm ClientAliveCountMax
Dmitry Belyavskiy 9dff9c
@@ -680,21 +676,22 @@ For this to work
Petr Šabata 81d24c
 .Cm GSSAPIKeyExchange
Petr Šabata 81d24c
 needs to be enabled in the server and also used by the client.
Petr Šabata 81d24c
 .It Cm GSSAPIKexAlgorithms
Petr Šabata 81d24c
+The default is handled system-wide by
Petr Šabata 81d24c
+.Xr crypto-policies 7 .
Petr Šabata 81d24c
+To see the defaults and how to modify this default, see manual page
Petr Šabata 81d24c
+.Xr update-crypto-policies 8 .
Petr Šabata 81d24c
+.Pp
Petr Šabata 81d24c
 The list of key exchange algorithms that are accepted by GSSAPI
Petr Šabata 81d24c
 key exchange. Possible values are
Petr Šabata 81d24c
 .Bd -literal -offset 3n
Petr Šabata 81d24c
-gss-gex-sha1-,
Petr Šabata 81d24c
-gss-group1-sha1-,
Petr Šabata 81d24c
-gss-group14-sha1-,
Petr Šabata 81d24c
-gss-group14-sha256-,
Petr Šabata 81d24c
-gss-group16-sha512-,
Petr Šabata 81d24c
-gss-nistp256-sha256-,
Petr Šabata 81d24c
+gss-gex-sha1-
Petr Šabata 81d24c
+gss-group1-sha1-
Petr Šabata 81d24c
+gss-group14-sha1-
Petr Šabata 81d24c
+gss-group14-sha256-
Petr Šabata 81d24c
+gss-group16-sha512-
Petr Šabata 81d24c
+gss-nistp256-sha256-
Petr Šabata 81d24c
 gss-curve25519-sha256-
Petr Šabata 81d24c
 .Ed
Petr Šabata 81d24c
-.Pp
Petr Šabata 81d24c
-The default is
Petr Šabata 81d24c
-.Dq gss-group14-sha256-,gss-group16-sha512-,gss-nistp256-sha256-,
Petr Šabata 81d24c
-gss-curve25519-sha256-,gss-group14-sha1-,gss-gex-sha1- .
Petr Šabata 81d24c
 This option only applies to connections using GSSAPI.
DistroBaker d029bb
 .It Cm HostbasedAcceptedAlgorithms
DistroBaker d029bb
 Specifies the signature algorithms that will be accepted for hostbased
Dmitry Belyavskiy 9dff9c
@@ -794,26 +791,13 @@ is specified, the location of the socket
Petr Šabata 81d24c
 .Ev SSH_AUTH_SOCK
Petr Šabata 81d24c
 environment variable.
Petr Šabata 81d24c
 .It Cm HostKeyAlgorithms
Petr Šabata 81d24c
+The default is handled system-wide by
Petr Šabata 81d24c
+.Xr crypto-policies 7 .
Petr Šabata 81d24c
+To see the defaults and how to modify this default, see manual page
Petr Šabata 81d24c
+.Xr update-crypto-policies 8 .
Petr Šabata 81d24c
+.Pp
DistroBaker d029bb
 Specifies the host key signature algorithms
Petr Šabata 81d24c
 that the server offers.
Petr Šabata 81d24c
-The default for this option is:
Petr Šabata 81d24c
-.Bd -literal -offset 3n
DistroBaker d029bb
-ssh-ed25519-cert-v01@openssh.com,
Petr Šabata 81d24c
-ecdsa-sha2-nistp256-cert-v01@openssh.com,
Petr Šabata 81d24c
-ecdsa-sha2-nistp384-cert-v01@openssh.com,
Petr Šabata 81d24c
-ecdsa-sha2-nistp521-cert-v01@openssh.com,
Petr Šabata 81d24c
-sk-ssh-ed25519-cert-v01@openssh.com,
DistroBaker d029bb
-sk-ecdsa-sha2-nistp256-cert-v01@openssh.com,
Petr Šabata 81d24c
-rsa-sha2-512-cert-v01@openssh.com,
Petr Šabata 81d24c
-rsa-sha2-256-cert-v01@openssh.com,
Petr Šabata 81d24c
-ssh-rsa-cert-v01@openssh.com,
DistroBaker d029bb
-ssh-ed25519,
Petr Šabata 81d24c
-ecdsa-sha2-nistp256,ecdsa-sha2-nistp384,ecdsa-sha2-nistp521,
DistroBaker d029bb
-sk-ssh-ed25519@openssh.com,
Petr Šabata 81d24c
-sk-ecdsa-sha2-nistp256@openssh.com,
Petr Šabata 81d24c
-rsa-sha2-512,rsa-sha2-256,ssh-rsa
Petr Šabata 81d24c
-.Ed
Petr Šabata 81d24c
-.Pp
DistroBaker d029bb
 The list of available signature algorithms may also be obtained using
Petr Šabata 81d24c
 .Qq ssh -Q HostKeyAlgorithms .
Petr Šabata 81d24c
 .It Cm IgnoreRhosts
Dmitry Belyavskiy 9dff9c
@@ -958,20 +942,25 @@ Specifies whether to look at .k5login fi
Petr Šabata 81d24c
 The default is
Petr Šabata 81d24c
 .Cm yes .
Petr Šabata 81d24c
 .It Cm KexAlgorithms
Petr Šabata 81d24c
+The default is handled system-wide by
Petr Šabata 81d24c
+.Xr crypto-policies 7 .
Petr Šabata 81d24c
+To see the defaults and how to modify this default, see manual page
Petr Šabata 81d24c
+.Xr update-crypto-policies 8 .
Petr Šabata 81d24c
+.Pp
Petr Šabata 81d24c
 Specifies the available KEX (Key Exchange) algorithms.
Petr Šabata 81d24c
 Multiple algorithms must be comma-separated.
Petr Šabata 81d24c
 Alternately if the specified list begins with a
Petr Šabata 81d24c
 .Sq +
Petr Šabata 81d24c
-character, then the specified methods will be appended to the default set
Petr Šabata 81d24c
-instead of replacing them.
Petr Šabata 81d24c
+character, then the specified methods will be appended to the built-in
Petr Šabata 81d24c
+openssh default set instead of replacing them.
Petr Šabata 81d24c
 If the specified list begins with a
Petr Šabata 81d24c
 .Sq -
Petr Šabata 81d24c
 character, then the specified methods (including wildcards) will be removed
Petr Šabata 81d24c
-from the default set instead of replacing them.
Petr Šabata 81d24c
+from the built-in openssh default set instead of replacing them.
Petr Šabata 81d24c
 If the specified list begins with a
Petr Šabata 81d24c
 .Sq ^
Petr Šabata 81d24c
 character, then the specified methods will be placed at the head of the
Petr Šabata 81d24c
-default set.
Petr Šabata 81d24c
+built-in openssh default set.
Petr Šabata 81d24c
 The supported algorithms are:
Petr Šabata 81d24c
 .Pp
Petr Šabata 81d24c
 .Bl -item -compact -offset indent
Dmitry Belyavskiy 9dff9c
@@ -1003,15 +992,6 @@ ecdh-sha2-nistp521
DistroBaker d029bb
 sntrup761x25519-sha512@openssh.com
Petr Šabata 81d24c
 .El
Petr Šabata 81d24c
 .Pp
Petr Šabata 81d24c
-The default is:
Petr Šabata 81d24c
-.Bd -literal -offset indent
Petr Šabata 81d24c
-curve25519-sha256,curve25519-sha256@libssh.org,
Petr Šabata 81d24c
-ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,
Petr Šabata 81d24c
-diffie-hellman-group-exchange-sha256,
Petr Šabata 81d24c
-diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,
Petr Šabata 81d24c
-diffie-hellman-group14-sha256
Petr Šabata 81d24c
-.Ed
Petr Šabata 81d24c
-.Pp
Petr Šabata 81d24c
 The list of available key exchange algorithms may also be obtained using
Petr Šabata 81d24c
 .Qq ssh -Q KexAlgorithms .
Petr Šabata 81d24c
 .It Cm ListenAddress
Dmitry Belyavskiy 9dff9c
@@ -1097,21 +1077,26 @@ function, and all code in the
DistroBaker d029bb
 file.
DistroBaker d029bb
 This option is intended for debugging and no overrides are enabled by default.
Petr Šabata 81d24c
 .It Cm MACs
Petr Šabata 81d24c
+The default is handled system-wide by
Petr Šabata 81d24c
+.Xr crypto-policies 7 .
Petr Šabata 81d24c
+To see the defaults and how to modify this default, see manual page
Petr Šabata 81d24c
+.Xr update-crypto-policies 8 .
Petr Šabata 81d24c
+.Pp
Petr Šabata 81d24c
 Specifies the available MAC (message authentication code) algorithms.
Petr Šabata 81d24c
 The MAC algorithm is used for data integrity protection.
Petr Šabata 81d24c
 Multiple algorithms must be comma-separated.
Petr Šabata 81d24c
 If the specified list begins with a
Petr Šabata 81d24c
 .Sq +
Petr Šabata 81d24c
-character, then the specified algorithms will be appended to the default set
Petr Šabata 81d24c
-instead of replacing them.
Petr Šabata 81d24c
+character, then the specified algorithms will be appended to the built-in
Petr Šabata 81d24c
+openssh default set instead of replacing them.
Petr Šabata 81d24c
 If the specified list begins with a
Petr Šabata 81d24c
 .Sq -
Petr Šabata 81d24c
 character, then the specified algorithms (including wildcards) will be removed
Petr Šabata 81d24c
-from the default set instead of replacing them.
Petr Šabata 81d24c
+from the built-in openssh default set instead of replacing them.
Petr Šabata 81d24c
 If the specified list begins with a
Petr Šabata 81d24c
 .Sq ^
Petr Šabata 81d24c
 character, then the specified algorithms will be placed at the head of the
Petr Šabata 81d24c
-default set.
Petr Šabata 81d24c
+built-in openssh default set.
Petr Šabata 81d24c
 .Pp
Petr Šabata 81d24c
 The algorithms that contain
Petr Šabata 81d24c
 .Qq -etm
Dmitry Belyavskiy 9dff9c
@@ -1154,15 +1139,6 @@ umac-64-etm@openssh.com
Petr Šabata 81d24c
 umac-128-etm@openssh.com
Petr Šabata 81d24c
 .El
Petr Šabata 81d24c
 .Pp
Petr Šabata 81d24c
-The default is:
Petr Šabata 81d24c
-.Bd -literal -offset indent
Petr Šabata 81d24c
-umac-64-etm@openssh.com,umac-128-etm@openssh.com,
Petr Šabata 81d24c
-hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,
Petr Šabata 81d24c
-hmac-sha1-etm@openssh.com,
Petr Šabata 81d24c
-umac-64@openssh.com,umac-128@openssh.com,
Petr Šabata 81d24c
-hmac-sha2-256,hmac-sha2-512,hmac-sha1
Petr Šabata 81d24c
-.Ed
Petr Šabata 81d24c
-.Pp
Petr Šabata 81d24c
 The list of available MAC algorithms may also be obtained using
Petr Šabata 81d24c
 .Qq ssh -Q mac .
Petr Šabata 81d24c
 .It Cm Match
Dmitry Belyavskiy 9dff9c
@@ -1541,37 +1517,25 @@ or equivalent.)
Petr Šabata 81d24c
 The default is
Petr Šabata 81d24c
 .Cm yes .
DistroBaker d029bb
 .It Cm PubkeyAcceptedAlgorithms
Petr Šabata 81d24c
+The default is handled system-wide by
Petr Šabata 81d24c
+.Xr crypto-policies 7 .
Petr Šabata 81d24c
+To see the defaults and how to modify this default, see manual page
Petr Šabata 81d24c
+.Xr update-crypto-policies 8 .
Petr Šabata 81d24c
+.Pp
DistroBaker d029bb
 Specifies the signature algorithms that will be accepted for public key
DistroBaker d029bb
 authentication as a list of comma-separated patterns.
Petr Šabata 81d24c
 Alternately if the specified list begins with a
Petr Šabata 81d24c
 .Sq +
DistroBaker d029bb
-character, then the specified algorithms will be appended to the default set
Petr Šabata 81d24c
-instead of replacing them.
DistroBaker d029bb
+character, then the specified algorithms will be appended to the built-in
Petr Šabata 81d24c
+openssh default set instead of replacing them.
Petr Šabata 81d24c
 If the specified list begins with a
Petr Šabata 81d24c
 .Sq -
DistroBaker d029bb
 character, then the specified algorithms (including wildcards) will be removed
Petr Šabata 81d24c
-from the default set instead of replacing them.
Petr Šabata 81d24c
+from the built-in openssh default set instead of replacing them.
Petr Šabata 81d24c
 If the specified list begins with a
Petr Šabata 81d24c
 .Sq ^
DistroBaker d029bb
 character, then the specified algorithms will be placed at the head of the
Petr Šabata 81d24c
-default set.
Petr Šabata 81d24c
-The default for this option is:
Petr Šabata 81d24c
-.Bd -literal -offset 3n
DistroBaker d029bb
-ssh-ed25519-cert-v01@openssh.com,
Petr Šabata 81d24c
-ecdsa-sha2-nistp256-cert-v01@openssh.com,
Petr Šabata 81d24c
-ecdsa-sha2-nistp384-cert-v01@openssh.com,
Petr Šabata 81d24c
-ecdsa-sha2-nistp521-cert-v01@openssh.com,
Petr Šabata 81d24c
-sk-ssh-ed25519-cert-v01@openssh.com,
DistroBaker d029bb
-sk-ecdsa-sha2-nistp256-cert-v01@openssh.com,
Petr Šabata 81d24c
-rsa-sha2-512-cert-v01@openssh.com,
Petr Šabata 81d24c
-rsa-sha2-256-cert-v01@openssh.com,
Petr Šabata 81d24c
-ssh-rsa-cert-v01@openssh.com,
DistroBaker d029bb
-ssh-ed25519,
Petr Šabata 81d24c
-ecdsa-sha2-nistp256,ecdsa-sha2-nistp384,ecdsa-sha2-nistp521,
DistroBaker d029bb
-sk-ssh-ed25519@openssh.com,
Petr Šabata 81d24c
-sk-ecdsa-sha2-nistp256@openssh.com,
Petr Šabata 81d24c
-rsa-sha2-512,rsa-sha2-256,ssh-rsa
Petr Šabata 81d24c
-.Ed
Petr Šabata 81d24c
+built-in openssh default set.
Petr Šabata 81d24c
 .Pp
DistroBaker d029bb
 The list of available signature algorithms may also be obtained using
DistroBaker d029bb
 .Qq ssh -Q PubkeyAcceptedAlgorithms .