summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorMatt Johnston <matt@ucc.asn.au>2013-04-03 00:43:31 +0800
committerMatt Johnston <matt@ucc.asn.au>2013-04-03 00:43:31 +0800
commit0edb52169005774051a49a7e515e753c1bd2dd76 (patch)
treee7bd424ec9a86b360f348d2612e16707bfd46ca6
parent7a320179658cd58d802a03b5c0c579f728ac044d (diff)
downloaddropbear-kexguess.tar.gz
Put some #ifdef options around first-follows options in case theykexguess
need to be disabled
-rw-r--r--cli-session.c5
-rw-r--r--common-algo.c2
-rw-r--r--common-kex.c4
-rw-r--r--sysoptions.h9
4 files changed, 19 insertions, 1 deletions
diff --git a/cli-session.c b/cli-session.c
index 9e64281..32b7ac7 100644
--- a/cli-session.c
+++ b/cli-session.c
@@ -110,11 +110,12 @@ void cli_session(int sock_in, int sock_out) {
}
+#ifdef USE_KEX_FIRST_FOLLOWS
static void cli_send_kex_first_guess() {
send_msg_kexdh_init();
dropbear_log(LOG_INFO, "kexdh_init guess sent");
- //cli_ses.kex_state = KEXDH_INIT_SENT;
}
+#endif
static void cli_session_init() {
@@ -155,7 +156,9 @@ static void cli_session_init() {
ses.isserver = 0;
+#ifdef USE_KEX_FIRST_FOLLOWS
ses.send_kex_first_guess = cli_send_kex_first_guess;
+#endif
}
diff --git a/common-algo.c b/common-algo.c
index b698611..c74463c 100644
--- a/common-algo.c
+++ b/common-algo.c
@@ -216,7 +216,9 @@ algo_type sshhostkey[] = {
algo_type sshkex[] = {
{"diffie-hellman-group14-sha1", DROPBEAR_KEX_DH_GROUP14, NULL, 1, NULL},
{"diffie-hellman-group1-sha1", DROPBEAR_KEX_DH_GROUP1, NULL, 1, NULL},
+#ifdef USE_KEXGUESS2
{KEXGUESS2_ALGO_NAME, KEXGUESS2_ALGO_ID, NULL, 1, NULL},
+#endif
{NULL, 0, NULL, 0, NULL}
};
diff --git a/common-kex.c b/common-kex.c
index eb1fd7b..6c22600 100644
--- a/common-kex.c
+++ b/common-kex.c
@@ -692,7 +692,11 @@ static void read_kex_algos() {
memset(ses.newkeys, 0x0, sizeof(*ses.newkeys));
+#ifdef USE_KEXGUESS2
enum kexguess2_used kexguess2 = KEXGUESS2_LOOK;
+#else
+ enum kexguess2_used kexguess2 = KEXGUESS2_NO;
+#endif
/* kex_algorithms */
algo = buf_match_algo(ses.payload, sshkex, &kexguess2, &goodguess);
diff --git a/sysoptions.h b/sysoptions.h
index 4d648c1..22c2a4d 100644
--- a/sysoptions.h
+++ b/sysoptions.h
@@ -23,6 +23,15 @@
#define AUTH_TIMEOUT 300 /* we choose 5 minutes */
#endif
+/* A client should try and send an initial key exchange packet guessing
+ * the algorithm that will match - saves a round trip connecting, has little
+ * overhead if the guess was "wrong". */
+#define USE_KEX_FIRST_FOLLOWS
+/* Use protocol extension to allow "first follows" to succeed more frequently.
+ * This is currently Dropbear-specific but will gracefully fallback when connecting
+ * to other implementations. */
+#define USE_KEXGUESS2
+
/* Minimum key sizes for DSS and RSA */
#ifndef MIN_DSS_KEYLEN
#define MIN_DSS_KEYLEN 512