mirror of
https://github.com/optim-enterprises-bv/vault.git
synced 2025-11-01 19:17:58 +00:00
Address algorithm not supported (#12852)
error seen on host /var/log/auth.log: userauth_pubkey: certificate signature algorithm ssh-rsa: signature algorithm not supported [preauth]
This commit is contained in:
@@ -475,7 +475,6 @@ forwarding. See [no prompt after login](#no-prompt-after-login) for examples.
|
||||
```
|
||||
|
||||
### Known Issues
|
||||
|
||||
- On SELinux-enforcing systems, you may need to adjust related types so that the
|
||||
SSH daemon is able to read it. For example, adjust the signed host certificate
|
||||
to be an `sshd_key_t` type.
|
||||
@@ -490,6 +489,17 @@ forwarding. See [no prompt after login](#no-prompt-after-login) for examples.
|
||||
[OpenSSH bug 2617](https://bugzilla.mindrot.org/show_bug.cgi?id=2617) for
|
||||
details.
|
||||
|
||||
- On some versions of SSH, you may get the following error on target host:
|
||||
|
||||
```text
|
||||
userauth_pubkey: certificate signature algorithm ssh-rsa: signature algorithm not supported [preauth]
|
||||
```
|
||||
Fix is to add below line to /etc/ssh/sshd_config
|
||||
```text
|
||||
CASignatureAlgorithms ^ssh-rsa
|
||||
```
|
||||
The ssh-rsa algorithm is no longer supported in [OpenSSH 8.2](https://www.openssh.com/txt/release-8.2)
|
||||
|
||||
## API
|
||||
|
||||
The SSH secrets engine has a full HTTP API. Please see the
|
||||
|
||||
Reference in New Issue
Block a user