feat(security): modernize SSH key algorithm support with Ed25519
Replace deprecated DSA key support with modern SSH key algorithms, prioritizing Ed25519 as the most secure option. Changes: - Add load_ssh_private_key() helper function in common.py - Support Ed25519 (preferred), ECDSA, and RSA key types - Remove deprecated and insecure DSA key support - Update all SSH key loading across backup drivers: * common.py: do_preexec, do_postexec, run_remote_command * backup_mysql.py * backup_pgsql.py * backup_sqlserver.py * backup_oracle.py * backup_samba4.py - Add ssh_port parameter to preexec/postexec connections - Update README.md with SSH key generation instructions - Document supported algorithms and migration path Algorithm priority: 1. Ed25519 (most secure, modern, fast, timing-attack resistant) 2. ECDSA (secure, widely supported) 3. RSA (legacy support, requires 2048+ bits) Security improvements: - Eliminates vulnerable DSA algorithm (1024-bit limit, FIPS deprecated) - Prioritizes elliptic curve cryptography (Ed25519, ECDSA) - Provides clear error messages for unsupported key types - Maintains backward compatibility with existing RSA keys Documentation: - Add SSH key generation examples to README.md - Update expected directory structure to show Ed25519 keys - Add migration notes in SECURITY_IMPROVEMENTS.md - Include key generation commands for all supported types Breaking change: - DSA keys are no longer supported and will fail with clear error message - Users must migrate to Ed25519, ECDSA, or RSA (4096-bit recommended) Migration: ```bash # Generate new Ed25519 key ssh-keygen -t ed25519 -f ~/.ssh/id_ed25519 # Copy to remote servers ssh-copy-id -i ~/.ssh/id_ed25519.pub user@remote ``` 🤖 Generated with [Claude Code](https://claude.com/claude-code) Co-Authored-By: Claude <noreply@anthropic.com>
This commit is contained in:
@@ -149,6 +149,83 @@ export TISBACKUP_SECRET_KEY=your-generated-key-here
|
||||
|
||||
**Security Impact:** Eliminates hardcoded secret in source code, prevents session hijacking and CSRF attacks
|
||||
|
||||
### 8. Modernized SSH Key Algorithm Support
|
||||
**Files Modified:** [libtisbackup/common.py](libtisbackup/common.py#L140), all backup drivers, [README.md](README.md)
|
||||
|
||||
**Before:**
|
||||
```python
|
||||
try:
|
||||
mykey = paramiko.RSAKey.from_private_key_file(self.private_key)
|
||||
except paramiko.SSHException:
|
||||
mykey = paramiko.DSSKey.from_private_key_file(self.private_key)
|
||||
```
|
||||
|
||||
**After:**
|
||||
```python
|
||||
def load_ssh_private_key(private_key_path):
|
||||
"""Load SSH private key with modern algorithm support.
|
||||
|
||||
Tries to load the key in order of preference:
|
||||
1. Ed25519 (most secure, modern)
|
||||
2. ECDSA (secure, widely supported)
|
||||
3. RSA (legacy, still secure with sufficient key size)
|
||||
|
||||
DSA is not supported as it's deprecated and insecure.
|
||||
"""
|
||||
key_types = [
|
||||
("Ed25519", paramiko.Ed25519Key),
|
||||
("ECDSA", paramiko.ECDSAKey),
|
||||
("RSA", paramiko.RSAKey),
|
||||
]
|
||||
|
||||
for key_name, key_class in key_types:
|
||||
try:
|
||||
return key_class.from_private_key_file(private_key_path)
|
||||
except paramiko.SSHException:
|
||||
continue
|
||||
|
||||
raise paramiko.SSHException(
|
||||
f"Unable to load private key. "
|
||||
f"Supported formats: Ed25519 (recommended), ECDSA, RSA. "
|
||||
f"DSA keys are no longer supported."
|
||||
)
|
||||
```
|
||||
|
||||
**Changes:**
|
||||
- Created centralized `load_ssh_private_key()` helper function
|
||||
- Updated all SSH key loading locations across codebase:
|
||||
- [common.py](libtisbackup/common.py): `do_preexec`, `do_postexec`, `run_remote_command`
|
||||
- [backup_mysql.py](libtisbackup/backup_mysql.py)
|
||||
- [backup_pgsql.py](libtisbackup/backup_pgsql.py)
|
||||
- [backup_sqlserver.py](libtisbackup/backup_sqlserver.py)
|
||||
- [backup_oracle.py](libtisbackup/backup_oracle.py)
|
||||
- [backup_samba4.py](libtisbackup/backup_samba4.py)
|
||||
- Removed deprecated DSA key support
|
||||
- Added Ed25519 as preferred algorithm
|
||||
- Added ECDSA as second choice
|
||||
- RSA remains supported for compatibility
|
||||
- Clear error message indicating DSA is no longer supported
|
||||
- Updated README.md with key generation instructions
|
||||
|
||||
**SSH Key Generation:**
|
||||
```bash
|
||||
# Ed25519 (recommended)
|
||||
ssh-keygen -t ed25519 -f ./ssh/id_ed25519 -C "tisbackup"
|
||||
|
||||
# ECDSA (also secure)
|
||||
ssh-keygen -t ecdsa -b 521 -f ./ssh/id_ecdsa
|
||||
|
||||
# RSA (legacy, minimum 4096 bits)
|
||||
ssh-keygen -t rsa -b 4096 -f ./ssh/id_rsa
|
||||
```
|
||||
|
||||
**Security Impact:**
|
||||
- Eliminates support for vulnerable DSA algorithm (1024-bit limit, FIPS deprecated)
|
||||
- Prioritizes Ed25519 (fast, secure, resistant to timing attacks)
|
||||
- Supports ECDSA as secure alternative
|
||||
- Maintains RSA compatibility for legacy systems
|
||||
- Clear migration path for users with old keys
|
||||
|
||||
## Remaining Security Issues (Critical - Not Fixed)
|
||||
|
||||
### 1. **No Authentication on Flask Routes**
|
||||
|
||||
Reference in New Issue
Block a user