[Gpg4win-devel] Putty and ECDSA support for gpg-agent in 2.0
Werner Koch
wk at gnupg.org
Fri Jul 5 14:12:48 CEST 2013
On Fri, 5 Jul 2013 12:06, bernhard at intevation.de said:
> So the question is: How do we advertise this functionality, so that people
> will try it? Could we come up with a question at first start in case putty is
> installed or something like this?
No.
Frankly, the use of public key authentication with ssh is still the
exception. Most people I asked didn't known how to use public key
authentication with ssh. Even server admins often don't know the
"PermitRootLogin without-password" clause of sshd and still allow
password authentication to root (or in a false sense of security via a
separate user and su). Sending passwords over an encrypted ssh channel
is in general not a good idea.
It is not the duty of the Gpg4win installer to educate users on
(advanced) use of ssh. This better done by a separate document.
And while we are at it: The need to click on the checkbox for the root
certificate readme in the installer is quite annoying. May I remove
that checkbox?
Salam-Shalom,
Werner
--
Die Gedanken sind frei. Ausnahmen regelt ein Bundesgesetz.
More information about the Gpg4win-devel
mailing list