curl / Mailing Lists / curl-users / Single Mail
Buy commercial curl support from WolfSSL. We help you work out your issues, debug your libcurl applications, use the API, port to new platforms, add new features and more. With a team lead by the curl founder himself.

RE: First version of curl to enable SHA256 for sftp

From: Werner L. Stolz via curl-users <curl-users_at_lists.haxx.se>
Date: Fri, 2 Sep 2022 21:39:00 +0000

I understand that you have to do a lot of guessing here.

It might be a long time before we get there, but if we still have trouble after we are able to update OpenSSH, perhaps we can pay for some support
to find a real fix.

Regarding libssh2, I am pretty sure we are using it. Here is the output from "curl --version"

curl 7.67.0 (powerpc-ibm-aix6.1.9.0) libcurl/7.67.0 OpenSSL/1.0.2t zlib/1.2.11 libssh2/1.8.2
Release-Date: 2019-11-06
Protocols: dict file ftp ftps gopher http https imap imaps ldap ldaps pop3 pop3s rtsp scp sftp smb smbs smtp smtps telnet tftp
Features: AsynchDNS GSS-API HTTPS-proxy IPv6 Kerberos Largefile libz NTLM NTLM_WB SPNEGO SSL TLS-SRP UnixSockets



Werner Stolz
InvestCloud, Inc.
LOS ANGELES – NEW YORK – LONDON – GENEVA – SINGAPORE – SYDNEY – ZURICH – VENICE – LUXEMBOURG – HONG KONG – TOKYO – BENGALURU – TORONTO – SAN FRANCISCO – TAMPA – CARLSBAD – NEW JERSEY
mobile: +1 331-238-3870 | office: +1 848-305-7158 | investcloud.com

-----Original Message-----
From: Daniel Stenberg <daniel_at_haxx.se>
Sent: Friday, September 2, 2022 4:30 PM
To: Werner L. Stolz via curl-users <curl-users_at_lists.haxx.se>
Cc: noloader_at_gmail.com; Werner L. Stolz <wstolz_at_investcloud.com>
Subject: RE: First version of curl to enable SHA256 for sftp

On Fri, 2 Sep 2022, Werner L. Stolz via curl-users wrote:

> This seems to indicate that I we can accelerate the remediation
> process, we can then simply put in a newer version of OpenSSH and have
> the problem go away without touching our curl application.

I doubt that will fix your issue. I rather suspect that you face this because your OpenSSH is *too new* or at least that it uses a configuration/setup that your version of libssh2 doesn't quite work with.

I think you can fix this by changing your OpenSSH config or updating your libssh2.

If indeed you are using libssh2 in your curl build.

This is a fair amount of me guessing though.

--
  / daniel.haxx.se
  | Commercial curl support up to 24x7 is available!
  | Private help, bug fixes, support, ports, new features
  | https://nam10.safelinks.protection.outlook.com/?url=https%3A%2F%2Fcurl.se%2Fsupport.html&amp;data=05%7C01%7Cwstolz%40investcloud.com%7C6607a723af654d1c523e08da8d2a46ec%7C134fa738eba84721a959151561c6c68e%7C0%7C0%7C637977509987314797%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%7C%7C%7C&amp;sdata=BYnk2jONocf5nWlJAA%2BrF3gZaMejZ7Fa8pSuEskzWKU%3D&amp;reserved=0
________________________________
Electronic Privacy Notice. This e-mail, and any attachments, contains information that is, or may be, covered by electronic communications privacy laws, and is also confidential and proprietary in nature. If you are not the intended recipient, please be advised that you are legally prohibited from retaining, using, copying, distributing, or otherwise disclosing this information in any manner. Instead, please reply to the sender that you have received this communication in error, and then immediately delete it. Thank you in advance for your cooperation.
________________________________
-- 
Unsubscribe: https://lists.haxx.se/listinfo/curl-users
Etiquette:   https://curl.se/mail/etiquette.html
Received on 2022-09-02