10/9 Shouldn't we upgrade to OpenSSH/OpenSSL soon?
\_ why "should" we? -shac
\_ Because of inherent weaknesses in the SSHv1
protocol that are corrected in SSHv2 which
\_ must protect uber-super-sekrit soda crap?!?
is implemented by OpenSSH.
\_ and why then should we use OpenSSH instead of the
free (to academic institutions) ssh2 server? -tom
\_ OpenSSH default install allows connections
to/from Either SSH 1or2 and at least one of
the commercial SSH2 servers doesn't pretend to
attempt validation on bad names. (not that
that matters on SODA) -crebbs
\_ the ssh2 server also allows connections to/from
either ssh 1 or 2. -tom |