Add SHA-256 and raw SSH host key inspection#104
Open
binaryfire wants to merge 1 commit into
Open
Conversation
Raise the libssh2 build floor to 1.9.0 so every successful build exposes the complete host-key API, and fail configuration clearly when headers and the linked library do not match.\n\nAdd SHA-256 fingerprint selection, raw negotiated host-key retrieval, and constants for the supported host-key types. Preserve the existing MD5 default and SHA-1 behavior.\n\nCover the new surface with an algorithm-independent PHPT that verifies the raw key and SHA-256 fingerprint describe the same negotiated server key.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Why
The extension currently exposes only MD5 and SHA-1 fingerprints. Applications implementing modern known-hosts or trust-on-first-use storage cannot retrieve the negotiated key bytes or algorithm.
libssh2 1.9.0 is the first release with the complete SHA-256 and host-key type surface used here. Configure failures now identify mismatched headers and libraries instead of silently building a reduced API.
Testing