moduli man page on QNX

Man page or keyword search:  
man Server   4347 pages
apropos Keyword Search (all sections)
Output format
QNX logo
[printable version]

MODULI(5)							     MODULI(5)

NAME
       moduli - Diffie Hellman moduli

DESCRIPTION
       The  /usr/pkg/usr/pkg/etc/ssh/moduli  file  contains  prime numbers and
       generators for use by sshd(8) in the Diffie-Hellman Group Exchange  key
       exchange method.

       New  moduli  may	 be  generated	with  ssh-keygen(1)  using  a two-step
       process.	 An initial candidategeneration	 pass,	using  ssh-keygen  -G,
       calculates  numbers  that  are  likely to be useful.  A second primali‐
       tytesting pass, using ssh-keygen -T provides a high degree of assurance
       that the numbers are prime and are safe for use in Diffie Hellman oper‐
       ations by sshd(8).  This moduli format is used as the output from  each
       pass.

       The  file  consists of newline-separated records, one per modulus, con‐
       taining seven space separated fields.  These fields are as follows:

       timestamp
	      The time that the modulus was last processed as YYYYMMDDHHMMSS.

       type   Decimal number specifying the internal structure	of  the	 prime
	      modulus.	Supported types are:

       0      Unknown, not tested

       2      "Safe" prime; (p-1)/2 is also prime.

       4      Sophie Germain; (p+1)*2 is also prime.

	      Moduli candidates initially produced by ssh-keygen(1) are Sophie
	      Germain primes (type 4).	Futher primality testing with ssh-key‐
	      gen(1)  produces	safe  prime moduli (type 2) that are ready for
	      use in sshd(8).  Other types are not used by OpenSSH.

       tests  Decimal number indicating the type of primality tests  that  the
	      number  has  been	 subjected  to represented as a bitmask of the
	      following values:

       0x00   Not tested

       0x01   Composite number - not prime.

       0x02   Sieve of Eratosthenes

       0x04   Probabalistic Miller-Rabin primality tests.

	      The ssh-keygen(1) moduli candidate generation uses the Sieve  of
	      Eratosthenes  (flag  0x02).   Subsequent ssh-keygen(1) primality
	      tests are Miller-Rabin tests (flag 0x04).

       trials Decimal number indicating of primaility trials  that  have  been
	      performed on the modulus.

       size   Decimal number indicating the size of the prime in bits.

       generator
	      The  recommended	generator for use with this modulus (hexadeci‐
	      mal).

       modulus
	      The modulus itself in hexadecimal.

	      When performing Diffie Hellman  Group  Exchange,	sshd(8)	 first
	      estimates	 the  size  of	the modulus required to produce enough
	      Diffie Hellman output to sufficiently key the selected symmetric
	      cipher.	sshd(8)	 then  randomly	 selects  a  modulus  from  Fa
	      /usr/pkg/usr/pkg/etc/ssh/moduli  that  best   meets   the	  size
	      requirement.

SEE ALSO
       ssh-keygen(1), sshd(8),

       Diffie-Hellman  Group  Exchange	for  the  Secure Shell (SSH) Transport
       Layer Protocol, RFC 4419, 2006.

				 June 26 2008			     MODULI(5)
[top]
                             _         _         _ 
                            | |       | |       | |     
                            | |       | |       | |     
                         __ | | __ __ | | __ __ | | __  
                         \ \| |/ / \ \| |/ / \ \| |/ /  
                          \ \ / /   \ \ / /   \ \ / /   
                           \   /     \   /     \   /    
                            \_/       \_/       \_/ 
More information is available in HTML format for server QNX

List of man pages available for QNX

Copyright (c) for man pages and the logo by the respective OS vendor.

For those who want to learn more, the polarhome community provides shell access and support.

[legal] [privacy] [GNU] [policy] [cookies] [netiquette] [sponsors] [FAQ]
Tweet
Polarhome, production since 1999.
Member of Polarhome portal.
Based on Fawad Halim's script.
....................................................................
Vote for polarhome
Free Shell Accounts :: the biggest list on the net