[28395] in North American Network Operators' Group
RE: ABOVE.NET SECURITY TRUTHS?
daemon@ATHENA.MIT.EDU (Chris Cappuccio)
Fri Apr 28 18:23:46 2000
Date: Fri, 28 Apr 2000 15:00:17 -0700 (PDT)
From: Chris Cappuccio <chris@dqc.org>
To: "Mr. James W. Laferriere" <babydr@baby-dragons.com>
Cc: "Greene, Dylan" <DGreene@NaviSite.com>,
'Paul Froutan' <pfroutan@rackspace.com>, rmeyer@mhsc.com,
nanog@merit.edu
In-Reply-To: <Pine.LNX.4.21.0004281429440.19257-100000@filesrv1.baby-dragons.com>
Message-ID: <Pine.BSO.4.21.0004281457540.31198-100000@dqc.org>
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset=US-ASCII
Errors-To: owner-nanog-outgoing@merit.edu
On Fri, 28 Apr 2000, Mr. James W. Laferriere wrote:
|
|
| Hello Dylan, Knew this was coming . But I'd hoped that
| the supported platforms would have been a little larger .
| Just the 7200 & UP . Seems cisco thinks ssh puts a bit
| of load on a cpu ? I can't see that for just a terminal
| session though . Twyl, JimL
|
The ssh server should optimally generate new keys every so often (every few
hours?)
This generally takes a lot of CPU time, and on a 2501 it would probably take
quite a while!!!
Also, the ssh server requires more memory then a telnet server. This is a
problem for older routers.
While I'm at it, I believe Cisco is/will be using the OpenSSH code for newer
implementations of ssh under IOS.
---
Reverend Chris Cappuccio
http://www.dqc.org/~chris/