@@ -70,6 +70,11 @@ for key in ${HOST_KEYS} ; do
echo " generating ssh ECDSA host key..."
generate_key $key ecdsa
;;
+ # match the hybrid key before the generic Ed25519 suffix
+ *_mldsa44_ed25519_key)
+ echo " generating ssh ML-DSA-44/ED25519 host key..."
+ generate_key $key mldsa44-ed25519
+ ;;
*_ed25519_key)
echo " generating ssh ED25519 host key..."
generate_key $key ed25519
@@ -20,6 +20,7 @@ Include /etc/ssh/sshd_config.d/*.conf
#HostKey /etc/ssh/ssh_host_rsa_key
#HostKey /etc/ssh/ssh_host_ecdsa_key
#HostKey /etc/ssh/ssh_host_ed25519_key
+#HostKey /etc/ssh/ssh_host_mldsa44_ed25519_key
# Ciphers and keying
#RekeyLimit default none
@@ -58,7 +58,7 @@ inherit autotools-brokensep ptest pkgconfig
# systemd-sshd-socket-mode means installing sshd.socket
# and systemd-sshd-service-mode corresponding to sshd.service
-PACKAGECONFIG ??= "systemd-sshd-socket-mode hostkey-ecdsa"
+PACKAGECONFIG ??= "systemd-sshd-socket-mode hostkey-ecdsa hostkey-mldsa44-ed25519"
PACKAGECONFIG[fido2] = "--with-security-key-builtin,--disable-security-key,libfido2"
PACKAGECONFIG[kerberos] = "--with-kerberos5,--without-kerberos5,krb5"
PACKAGECONFIG[ldns] = "--with-ldns,--without-ldns,ldns"
@@ -69,6 +69,7 @@ PACKAGECONFIG[systemd-sshd-service-mode] = ""
PACKAGECONFIG[hostkey-rsa] = ""
PACKAGECONFIG[hostkey-ecdsa] = ""
PACKAGECONFIG[hostkey-ed25519] = ""
+PACKAGECONFIG[hostkey-mldsa44-ed25519] = ""
# login path is hardcoded in sshd
EXTRA_OECONF = "'LOGIN_PROGRAM=${base_bindir}/login' \
@@ -127,6 +128,9 @@ sshd_hostkey_setup() {
if ${@bb.utils.contains('PACKAGECONFIG','hostkey-ed25519','true','false',d)}; then
echo "HostKey ${OPENSSH_HOST_KEY_DIR}/ssh_host_ed25519_key" >> ${D}${sysconfdir}/ssh/sshd_config
fi
+ if ${@bb.utils.contains('PACKAGECONFIG','hostkey-mldsa44-ed25519','true','false',d)}; then
+ echo "HostKey ${OPENSSH_HOST_KEY_DIR}/ssh_host_mldsa44_ed25519_key" >> ${D}${sysconfdir}/ssh/sshd_config
+ fi
sed -i '/HostKey/d' ${D}${sysconfdir}/ssh/sshd_config_readonly
if ${@bb.utils.contains('PACKAGECONFIG','hostkey-rsa','true','false',d)}; then
@@ -138,6 +142,9 @@ sshd_hostkey_setup() {
if ${@bb.utils.contains('PACKAGECONFIG','hostkey-ed25519','true','false',d)}; then
echo "HostKey ${OPENSSH_HOST_KEY_DIR_READONLY_CONFIG}/ssh_host_ed25519_key" >> ${D}${sysconfdir}/ssh/sshd_config_readonly
fi
+ if ${@bb.utils.contains('PACKAGECONFIG','hostkey-mldsa44-ed25519','true','false',d)}; then
+ echo "HostKey ${OPENSSH_HOST_KEY_DIR_READONLY_CONFIG}/ssh_host_mldsa44_ed25519_key" >> ${D}${sysconfdir}/ssh/sshd_config_readonly
+ fi
}
do_install:append () {
OpenSSH 10.6 enables the hybrid ML-DSA-44/Ed25519 signature algorithm. Enable this PQ host key type by default beside ECDSA for normal and read-only configurations. Match the hybrid filename before the Ed25519 suffix to avoid generating a classical key for the hybrid key path. Signed-off-by: Ayoub Zaki <ayoub.zaki@embetrix.com> --- .../recipes-connectivity/openssh/openssh/sshd_check_keys | 5 +++++ meta/recipes-connectivity/openssh/openssh/sshd_config | 1 + meta/recipes-connectivity/openssh/openssh_10.6p1.bb | 9 ++++++++- 3 files changed, 14 insertions(+), 1 deletion(-)