Comprehensive data protection for all workloads
Post Reply
swimboy
Lurker
Posts: 1
Liked: 6 times
Joined: Feb 07, 2019 5:48 pm
Full Name: Jeff M
Contact:

Feature Request: Support SSH2 format for keys used for linux credentials

Post by swimboy » 6 people like this post

When enabling guest processing for linux VMs, currently keys must be in ssh.com format and not SSH2. Tutorials exist for using PuTTYgen to convert to the ssh.com format. However, ed25519 keys cannot be converted, since the ssh.com format was deprecated before the development of ed25519.

In short, we have deployed ed25519 keys extensively in our environment, and eliminated RSA keys. While recent versions of PuTTY have no problem using ed25519 keys, and it's been the default for OpenSSH on linux since 2014, Veeam can't import them because they can only be created in SSH2 format, and not the older ssh.com format.
tsightler
VP, Product Management
Posts: 6009
Liked: 2842 times
Joined: Jun 05, 2009 12:57 pm
Full Name: Tom Sightler
Contact:

Re: Feature Request: Support SSH2 format for keys used for linux credentials

Post by tsightler » 4 people like this post

Even if you could import these keys, they won't work, because the current SSH libraries in use doesn't have support for any elliptical curve algorithms. So this request is really to add support for the ed25519 algorithm to the product, so that it can support such keys. It's a good request, one that I've recently voiced myself internally, but unfortunately, is non-trivial. That's not to say it's not important, or shouldn't be done, but only to set proper expectations that it might not be right around the corner.
BrianBuchanan
Enthusiast
Posts: 52
Liked: 9 times
Joined: Nov 29, 2019 12:56 pm
Full Name: Brian Buchanan
Contact:

Re: Feature Request: Support SSH2 format for keys used for linux credentials

Post by BrianBuchanan »

I am also looking for support of ed25519 keys. Is there a way to formally request this feature?

Edit: I have opened case #04325326 requesting a timeline for implementation.
Gostev
Chief Product Officer
Posts: 31457
Liked: 6647 times
Joined: Jan 01, 2006 1:01 am
Location: Baar, Switzerland
Contact:

Re: Feature Request: Support SSH2 format for keys used for linux credentials

Post by Gostev » 1 person likes this post

Most likely, support for elliptical curve algorithms will be added in v11.
colohost
Service Provider
Posts: 35
Liked: 3 times
Joined: Jan 14, 2019 10:09 pm
Full Name: Colo Host
Contact:

Re: Feature Request: Support SSH2 format for keys used for linux credentials

Post by colohost »

Just wanted to confirm this did not yet end up in 11? I just tried to add an ed25519 key and it didn't recognize it.
PTide
Product Manager
Posts: 6408
Liked: 724 times
Joined: May 19, 2015 1:46 pm
Contact:

Re: Feature Request: Support SSH2 format for keys used for linux credentials

Post by PTide »

Hi,

Unfortunately v11 does not support EC-based keys for authentication yet - only EC based key exchange and encryption are supported. For authentication purposes only RSA is supported for now.

Support for authentication via EC keys will be added in a later update.

Thanks!
jvandevelde
Influencer
Posts: 13
Liked: 2 times
Joined: Mar 22, 2010 11:57 am
Full Name: Johan van de Velde
Contact:

Re: Feature Request: Support SSH2 format for keys used for linux credentials

Post by jvandevelde »

Support for ed25519 keys is also something that we are eagerly waiting for.
Would you mind sharing when the 'later update' containing this enhancement is going to be released?
Gostev
Chief Product Officer
Posts: 31457
Liked: 6647 times
Joined: Jan 01, 2006 1:01 am
Location: Baar, Switzerland
Contact:

Re: Feature Request: Support SSH2 format for keys used for linux credentials

Post by Gostev »

Unfortunately, we cannot make comments regarding dates. Thanks!
Post Reply

Who is online

Users browsing this forum: ante_704, srlarsen and 165 guests