[28395] in North American Network Operators' Group

home help back first fref pref prev next nref lref last post

RE: ABOVE.NET SECURITY TRUTHS?

daemon@ATHENA.MIT.EDU (Chris Cappuccio)
Fri Apr 28 18:23:46 2000

Date: Fri, 28 Apr 2000 15:00:17 -0700 (PDT)
From: Chris Cappuccio <chris@dqc.org>
To: "Mr. James W. Laferriere" <babydr@baby-dragons.com>
Cc: "Greene, Dylan" <DGreene@NaviSite.com>,
	'Paul Froutan' <pfroutan@rackspace.com>, rmeyer@mhsc.com,
	nanog@merit.edu
In-Reply-To: <Pine.LNX.4.21.0004281429440.19257-100000@filesrv1.baby-dragons.com>
Message-ID: <Pine.BSO.4.21.0004281457540.31198-100000@dqc.org>
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset=US-ASCII
Errors-To: owner-nanog-outgoing@merit.edu


On Fri, 28 Apr 2000, Mr. James W. Laferriere wrote:

 | 
 | 
 | 	Hello Dylan,  Knew this was coming .  But I'd hoped that 
 | 	the supported platforms would have been a little larger .
 | 	Just the 7200 & UP .  Seems cisco thinks ssh puts a bit
 | 	of load on a cpu ?  I can't see that for just a terminal
 | 	session though .  Twyl,  JimL
 | 

The ssh server should optimally generate new keys every so often (every few
hours?)

This generally takes a lot of CPU time, and on a 2501 it would probably take
quite a while!!!

Also, the ssh server requires more memory then a telnet server.  This is a
problem for older routers.

While I'm at it, I believe Cisco is/will be using the OpenSSH code for newer
implementations of ssh under IOS.

---
Reverend Chris Cappuccio
http://www.dqc.org/~chris/




home help back first fref pref prev next nref lref last post