Post-quantum safe kex algorythm?
Nobody has claimed this yet.
- Dominant language
- JavaScript
- Stars
- 5.8k
- Forks
- 734
- PR merge metrics
- No merged PRs in 30d
Description
Using ssh2 via Azure pipelines and failing to connect to an ssh server that only has
KexAlgorithms sntrup761x25519-sha512@openssh.com
The version used is https://github.com/microsoft/azure-pipelines-tasks/blob/master/Tasks/CopyFilesOverSSHV0/package.json#L26
"ssh2": "^1.15.0",
"ssh2-sftp-client": "^12.0.1"
Is this expected, or does Microsoft need to update ssh2? I was not able to find any hints.
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
The report identifies Tasks/CopyFilesOverSSHV0/package.json and the ssh2 1.15.0 dependency; start by checking which key-exchange algorithms that version supports. Reproduce the connection against a server offering only sntrup761x25519-sha512@openssh.com. Done means the compatibility behavior is confirmed and the supported or unsupported outcome is clearly documented.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- javascript, node.js
- Domain
- networking, security
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Quiet
- Clarity
- Needs clarification
- Newbie friendliness
- 45/100