Hi Team,
Servers can have multiple hostkeys with different algorithms(rsa, ed25519,ecdsa etc). Similarly multiple server(host) certs for each algorithms can be imported to be used in host key validation.
In case of multiple certs on same host (assuming all have same hiba extensions) which algorithms should be priotised for client certificates hiba extension validation.
Should it be based on sshd_config which HostCertificate entry comes first.
(if all host certs have same extension using anyone should pass but if we have a documentation around it, that will be great)
Hi Team,
Servers can have multiple hostkeys with different algorithms(rsa, ed25519,ecdsa etc). Similarly multiple server(host) certs for each algorithms can be imported to be used in host key validation.
In case of multiple certs on same host (assuming all have same hiba extensions) which algorithms should be priotised for client certificates hiba extension validation.
Should it be based on sshd_config which HostCertificate entry comes first.
(if all host certs have same extension using anyone should pass but if we have a documentation around it, that will be great)