Repository navigation
Expand file tree
/
Copy pathssh_algorithm.dart
More file actions
105 lines (95 loc) · 3.4 KB
/
Copy pathssh_algorithm.dart
File metadata and controls
105 lines (95 loc) · 3.4 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
import 'package:zest_ssh_core/src/algorithm/ssh_cipher_type.dart';
import 'package:zest_ssh_core/src/algorithm/ssh_hostkey_type.dart';
import 'package:zest_ssh_core/src/algorithm/ssh_kex_type.dart';
import 'package:zest_ssh_core/src/algorithm/ssh_mac_type.dart';
abstract class SSHAlgorithm {
/// The name of the algorithm.
String get name;
const SSHAlgorithm();
@override
String toString() {
return '$runtimeType($name)';
}
}
extension SSHAlgorithmList<T extends SSHAlgorithm> on List<T> {
List<String> toNameList() {
return map((algorithm) => algorithm.name).toList();
}
T? getByName(String name) {
for (var algorithm in this) {
if (algorithm.name == name) {
return algorithm;
}
}
return null;
}
}
class SSHAlgorithms {
/// Algorithm used for the key exchange.
final List<SSHKexType> kex;
/// Algorithm used for the host key.
final List<SSHHostkeyType> hostkey;
/// Algorithm used for the encryption.
final List<SSHCipherType> cipher;
/// Algorithm used for the authentication.
final List<SSHMacType> mac;
const SSHAlgorithms({
this.kex = const [
// Post-quantum hybrid first: an OpenSSH 9.9+ server picks it, an
// older server simply does not list it and we fall through.
SSHKexType.mlkem768x25519,
SSHKexType.sntrup761x25519,
SSHKexType.sntrup761x25519OpenSSH,
SSHKexType.x25519,
SSHKexType.x25519Iana,
SSHKexType.nistp521,
SSHKexType.nistp384,
SSHKexType.nistp256,
SSHKexType.dhGexSha256,
SSHKexType.dh14Sha256,
// SHA-1 key exchanges (dh14Sha1, dhGexSha1) removed from defaults -
// SHA-1 is collision-broken, so the strong defaults must not be
// negotiable down to it. Opt-in only via the compatibility profile
// (custom SSHAlgorithms). dh1Sha1 (1024-bit DH Group 1) likewise
// excluded.
],
this.hostkey = const [
SSHHostkeyType.ed25519,
SSHHostkeyType.rsaSha512,
SSHHostkeyType.rsaSha256,
// rsaSha1 (ssh-rsa, SHA-1 signatures) removed from defaults - a
// downgrade to SHA-1 host-key signatures must be opt-in only via the
// compatibility profile, not offered to every server by default.
SSHHostkeyType.ecdsa521,
SSHHostkeyType.ecdsa384,
SSHHostkeyType.ecdsa256,
// Ed448 not offered by default until sign_dart is vetted
// SSHHostkeyType.ed448,
],
this.cipher = const [
SSHCipherType.chacha20poly1305,
// Prefer the 256-bit key over the 128-bit one when a server offers
// both - a security-forward client should negotiate the stronger
// cipher first.
SSHCipherType.aes256ctr,
SSHCipherType.aes128ctr,
// CBC mode ciphers removed from defaults - CVE-2008-5161 plaintext
// recovery when not paired with ETM MACs. Opt-in via custom
// SSHAlgorithms if required for legacy servers.
],
this.mac = const [
// ETM (Encrypt-Then-MAC) variants are strongest -- prefer them.
SSHMacType.hmacSha512Etm,
SSHMacType.hmacSha256Etm,
// Full-length HMAC variants next.
SSHMacType.hmacSha512,
SSHMacType.hmacSha256,
SSHMacType.hmacSha1,
// Truncated 96-bit MACs are weaker -- list last.
SSHMacType.hmacSha512_96,
SSHMacType.hmacSha256_96,
// hmac-md5 removed from defaults - MD5 is deprecated.
// Opt-in via custom SSHAlgorithms if required for legacy servers.
],
});
}