|
|
|
|
|
by rollcat
958 days ago
|
|
> openssh uses openssl's RSA implementation Upstream OpenSSH uses LibreSSL, which they've forked from OpenSSL precisely because they were concerned with code quality and correctness. I don't know whether this problem affects LibreSSL, but one of their main goals was to be less afraid of breaking the OpenSSL API to fix usability problems that lead to incorrect (insecure) code. |
|
Look for the comment: