Community discussions

MikroTik App
th0massin0
Member Candidate
Member Candidate
Topic Author
Posts: 156
Joined: Sun May 11, 2014 4:16 am
Location:Poland

Feature Request: Ed25519 SSH keys

Tue Jun 07, 2016 1:20 pm

As in subject, everybody will sleep better if the support of Ed25519 keys will be available in ROS7 (or 6!)
Top
azol
just joined
Posts: 4
Joined: Thu Sep 28, 2017 5:06 pm

Re: Feature Request: Ed25519 SSH keys

Tue Oct 03, 2017 6:18 pm

agree, +1
Top
WzL
just joined
Posts: 9
Joined: Tue Dec 02, 2014 4:00 pm

Re: Feature Request: Ed25519 SSH keys

Thu Nov 16, 2017 10:24 pm

+1, this feature is much missed here!
Top
User avatar
Anastasia
Frequent Visitor
Frequent Visitor
Posts: 55
Joined: Wed Oct 28, 2015 7:12 pm

Re: Feature Request: Ed25519 SSH keys

Mon Jan 28, 2019 3:06 pm

+1 add support Ed25519.
Top
cypa
newbie
Posts: 25
Joined: Mon Apr 01, 2013 11:20 am

Re: Feature Request: Ed25519 SSH keys

Mon Mar 23, 2020 1:34 pm

+1 we need this!!!
Top
msatter
Forum Guru
Forum Guru
Posts: 2866
Joined: Tue Feb 18, 2014 12:56 am
Location:Netherlands / Nīderlande

Re: Feature Request: Ed25519 SSH keys

Mon Mar 23, 2020 1:47 pm

Top
cypa
newbie
Posts: 25
Joined: Mon Apr 01, 2013 11:20 am

Re: Feature Request: Ed25519 SSH keys

Mon Mar 23, 2020 1:58 pm

OK could you please hint what do I do wrong?
Code:Select all
[cypa@hAP.k16] > user ssh-keys import public-key-file=id_ed25519.pub unable to load key file (wrong format?) ! [cypa@hAP.k16] > system resource print uptime: 56m26s version: 6.46.4 (stable) build-time: Feb/21/2020 11:26:37 factory-software: 6.34.2 free-memory: 6.4MiB total-memory: 32.0MiB cpu: MIPS 24Kc V7.4 cpu-count: 1 cpu-frequency: 650MHz cpu-load: 7% free-hdd-space: 7.7MiB total-hdd-space: 16.0MiB write-sect-since-reboot: 115 write-sect-total: 30299 bad-blocks: 0% architecture-name: smips board-name: hAP lite platform: MikroTik [cypa@hAP.k16] >
Top
User avatar
eworm
Forum Guru
Forum Guru
Posts: 1034
Joined: Wed Oct 22, 2014 9:23 am
Location:Oberhausen, Germany
Contact:

Re: Feature Request: Ed25519 SSH keys

Mon Mar 23, 2020 3:24 pm

Nothing wrong, ed25519 is not supported.
Top
VVL
just joined
Posts: 1
Joined: Thu Sep 03, 2020 1:48 am

Re: Feature Request: Ed25519 SSH keys

Thu Sep 03, 2020 1:53 am

Nothing wrong, ed25519 is not supported.
In 7.1beta2 wireguard protocol was added. It use ed25519 as one of algorithm. Maybe it possible to add ssh support of this algo too?
Top
Markg23
just joined
Posts: 5
Joined: Sun Oct 25, 2020 8:44 am
Location:Spain

Re: Feature Request: Ed25519 SSH keys

Tue Dec 08, 2020 1:39 pm

+1 It would be great if RouterOS support ssh Ed25519 keys
Top
User avatar
mkx
Forum Guru
Forum Guru
Posts: 10139
Joined: Thu Mar 03, 2016 10:23 pm

Re: Feature Request: Ed25519 SSH keys

Tue Dec 08, 2020 9:05 pm

In 7.1beta2 wireguard protocol was added. It use ed25519 as one of algorithm. Maybe it possible to add ssh support of this algo too?

wireguard and ssh don't necessarily share encryption libraries so support for certain key types in one of these services doesn't mean support for same key type in the other service. However the trend in IT is to re-use things and hopefully wireguard and ssh will share encryption library ... not only to provide same level of support for key types but to reduce size of install as well.
Top
akschu
Frequent Visitor
Frequent Visitor
Posts: 56
Joined: Thu Mar 15, 2012 2:09 am

Re: Feature Request: Ed25519 SSH keys

Tue Jun 22, 2021 9:55 pm

Please! I'm deploying cert based auth and this is needed.
Top
User avatar
Paradox
just joined
Posts: 20
Joined: Fri Oct 15, 2021 3:50 pm

Re: Feature Request: Ed25519 SSH keys

Fri Oct 15, 2021 3:53 pm

Hi,

I'd like to use Ed25519 SSH keys, too. I do not use any other key formats anymore.

Please add it!
Top
yottabit
Member Candidate
Member Candidate
Posts: 198
Joined: Thu Feb 21, 2013 5:56 am

Re: Feature Request: Ed25519 SSH keys

Thu Nov 25, 2021 5:51 pm

6.49.1 here and still no support for ed25519 keys. As I can no longer use sha-1 RSA keys, I would like to use the currently most secure format and not manage so many different keys just because a vendor refuses to update security to the best practices.

Can we get ed25519 support in v6 please??

Edit: I can't even get ecdsa to import, sigh.

Edit 2: workaround for now is to use rsa-sha2-256, which is still not as secure as ed25519 but it's the best that RouterOS v6 currently supports. To generate this key using openssh:
Code:Select all
$ ssh-keygen -t rsa-sha2-256
I'm still going to be maintaining this weaker key for RouterOS only, and an ed25519 key for everything else.
Last edited byyottabiton Thu Nov 25, 2021 6:12 pm, edited 2 times in total.
Top
User avatar
eworm
Forum Guru
Forum Guru
Posts: 1034
Joined: Wed Oct 22, 2014 9:23 am
Location:Oberhausen, Germany
Contact:

Re: Feature Request: Ed25519 SSH keys

Thu Nov 25, 2021 5:54 pm

I have a support/feature ticket on that topic (SUP-61929). Answer from MikroTik:
Thank you for your feedback. We will consider adding this feature in the future.
That's better than 'No' I guess... So go and place your own issue...
Top
yottabit
Member Candidate
Member Candidate
Posts: 198
Joined: Thu Feb 21, 2013 5:56 am

Re: Feature Request: Ed25519 SSH keys

Thu Nov 25, 2021 6:15 pm

Done, SUP-67007.
Top
guipoletto
Member Candidate
Member Candidate
Posts: 183
Joined: Mon Sep 19, 2011 5:31 am

Re: Feature Request: Ed25519 SSH keys

Thu Nov 25, 2021 11:20 pm

Done, SUP-67007.
did they offer a timeline?
Top
msatter
Forum Guru
Forum Guru
Posts: 2866
Joined: Tue Feb 18, 2014 12:56 am
Location:Netherlands / Nīderlande

Re: Feature Request: Ed25519 SSH keys

Thu Nov 25, 2021 11:49 pm

I only know the start of the first request and that was more than 5 years ago.
Top
User avatar
eworm
Forum Guru
Forum Guru
Posts: 1034
Joined: Wed Oct 22, 2014 9:23 am
Location:Oberhausen, Germany
Contact:

Re: Feature Request: Ed25519 SSH keys

Fri Nov 26, 2021 12:35 am

Timeline? Currently we do not know whether or not we will see this any time soon or at all.
So if you want this... Open your own issue to make Mikrotik aware of the interest.
Top
User avatar
osc86
Member Candidate
Member Candidate
Posts: 194
Joined: Wed Aug 09, 2017 1:15 pm

Re: Feature Request: Ed25519 SSH keys

Tue Apr 12, 2022 6:00 pm

It seems we first need support for modern signature algorithms (rsa-sha2-256/512, ssh-ed25519, ecdsa-sha2-nistp256/384/521).
OpenSSH 9.0的发布,将officially deprecated and disabled by default, which seems to be the only supported algorithm in RouterOS 6+7 (next to ssh-dss, also deprecated).
Connecting to the router using a rsa key now fails, and adding an exception to allow ssh-rsa again on every machine running openssh 9.0+ is not an option.
Top
yottabit
Member Candidate
Member Candidate
Posts: 198
Joined: Thu Feb 21, 2013 5:56 am

Re: Feature Request: Ed25519 SSH keys

Tue Apr 12, 2022 9:17 pm

Done, SUP-67007.
did they offer a timeline?
不。他们没有提交到v6,只是说"shortly" for v7. That was on 2021-12-28. No updates since.
Top
User avatar
CarlitoxxPro
newbie
Posts: 34
Joined: Wed Jan 04, 2017 10:15 am
Location:Spain
Contact:

Re: Feature Request: Ed25519 SSH keys

Mon Jun 20, 2022 1:55 pm

+1, this should be a must

@strods, please could you ping internally to the security team and let us know if is in the roadmap and what is the ETA.

Thanks in advance.
Top
mikrotip
just joined
Posts: 2
Joined: Sat Sep 10, 2022 3:46 pm

Re: Feature Request: Ed25519 SSH keys

Sat Sep 10, 2022 5:01 pm

What is the problem? 6 years passed. Is there some update about the feature?
Top
User avatar
foorschtbar
just joined
Posts: 7
Joined: Wed Oct 13, 2021 12:41 am

Re: Feature Request: Ed25519 SSH keys

Wed Sep 21, 2022 4:01 pm

I switched to ed25519 and my Mikrotik devices are the only ones that don't support it yet:(
Top
User avatar
rextended
Forum Guru
Forum Guru
Posts: 11472
Joined: Tue Feb 25, 2014 12:49 pm
Location:Italy
Contact:

Re: Feature Request: Ed25519 SSH keys

Wed Sep 21, 2022 4:05 pm

Patience, you don't have to protect the "Deutsche Bank" anyway, right?
Top
tangent
Forum Veteran
Forum Veteran
Posts: 949
Joined: Thu Jul 01, 2021 3:15 pm

Re: Feature Request: Ed25519 SSH keys

Thu Sep 22, 2022 1:15 am

Six years stretches the word “patience” all out of shape.

This in a world where RouterOS has dropped DSA (as it should) leaving only the semi-obsolescent RSA, a tech older than most of the board’s participants, I’d warrant.

It’s past time for this lack to be filled. The option to DIY a fix for ourselves with containers is either unavailable or unpalatable: most devices aren’t ARM, and even with those that are, a scripted bounce thru an OpenSSH container sucks.

Get it done, MikroTik!
Top
User avatar
foorschtbar
just joined
Posts: 7
Joined: Wed Oct 13, 2021 12:41 am

Re: Feature Request: Ed25519 SSH keys

Thu Sep 22, 2022 2:13 pm

Patience, you don't have to protect the "Deutsche Bank" anyway, right?
When u today create a new Keypair, why not use ED25519? There more improvements, like the shorter keys, and not only MoRE SEcuRe!!!11elf
Top
yottabit
Member Candidate
Member Candidate
Posts: 198
Joined: Thu Feb 21, 2013 5:56 am

Re: Feature Request: Ed25519 SSH keys

Thu Sep 22, 2022 4:38 pm

Most of my ssh hosts won't even accept rsa keys anymore. So I have to maintain ed25519 for them, and a separate rsa key just for the RouterOS hosts. It's very annoying.
Top
gazmirb
just joined
Posts: 1
Joined: Sun Jan 22, 2023 1:42 pm

Re: Feature Request: Ed25519 SSH keys

Sun Jan 22, 2023 1:45 pm

either with update 7.7 my mikrotik doesnt support Ed25519 key:?
Top
User avatar
shalak
newbie
Posts: 38
Joined: Sat Aug 24, 2019 11:47 am

Re: Feature Request: Ed25519 SSH keys

Sun Jan 22, 2023 9:05 pm

As of the most recent macOS update (Ventura, 13.1), by default it no longer allows RSA to be used for SSH client.

You have to explicitly allow it in SSH config:
Code:Select all
Host * PubkeyAcceptedKeyTypes=+ssh-rsa HostKeyAlgorithms=+ssh-rsa
Any updates on implementing ed25519?
Top
yottabit
Member Candidate
Member Candidate
Posts: 198
Joined: Thu Feb 21, 2013 5:56 am

Re: Feature Request: Ed25519 SSH keys

Sun Jan 22, 2023 9:10 pm

6.5 years since original post. 2 years since they said "shortly" in my ticket. We need a reference for what "shortly" means in this case? Software dev cycles? Human lifespan? Galactic time scale?
Top
fmikker
just joined
Posts: 2
Joined: Tue Oct 17, 2017 11:00 pm

Re: Feature Request: Ed25519 SSH keys

Tue Jan 31, 2023 5:04 pm

I'm still waiting too..
Top
seb13
just joined
Posts: 10
Joined: Mon Sep 12, 2016 10:11 pm

Re: Feature Request: Ed25519 SSH keys

Thu Feb 02, 2023 5:10 pm

+1!
Top
Naoy
just joined
Posts: 1
Joined: Wed Mar 08, 2023 12:13 am

Re: Feature Request: Ed25519 SSH keys

Wed Mar 08, 2023 12:17 am

We're in 2023 and Ed25519, the most used ECDH protocol, is still not supported...
Top
User avatar
eworm
Forum Guru
Forum Guru
Posts: 1034
Joined: Wed Oct 22, 2014 9:23 am
Location:Oberhausen, Germany
Contact:

Re: Feature Request: Ed25519 SSH keys

Wed Mar 08, 2023 10:13 pm

Perhaps in 7.9beta?*holding thumbs*
Top
majestic
Frequent Visitor
Frequent Visitor
Posts: 90
Joined: Mon Dec 05, 2016 11:19 am

Re: Feature Request: Ed25519 SSH keys

Wed Mar 08, 2023 10:46 pm

+1 this should really of been added in many years ago. This should not be too hard to implment.
Top
User avatar
rextended
Forum Guru
Forum Guru
Posts: 11472
Joined: Tue Feb 25, 2014 12:49 pm
Location:Italy
Contact:

Re: Feature Request: Ed25519 SSH keys

Wed Mar 08, 2023 11:22 pm

This should not be too hard to implment.
Like count on BGP routes?
Top
Sob
Forum Guru
Forum Guru
Posts: 9185
Joined: Mon Apr 20, 2009 9:11 pm

Re: Feature Request: Ed25519 SSH keys

Thu Mar 09, 2023 12:09 am

Reinventing the wheel properly takes time.;)And they like to do it a lot, example:viewtopic.php?p=965896#p965896
Top
JohnConnett
just joined
Posts: 21
Joined: Thu Feb 23, 2023 2:27 pm

Re: Feature Request: Ed25519 SSH keys

Fri Mar 10, 2023 1:10 pm

+1. Really surprised thisstillisn't supported in 2023!
Top
User avatar
Paradox
just joined
Posts: 20
Joined: Fri Oct 15, 2021 3:50 pm

Re: Feature Request: Ed25519 SSH keys

Mon Mar 20, 2023 5:39 pm

I have a support/feature ticket on that topic (SUP-61929).
Also did a feature request...
Top
laca77
just joined
Posts: 14
Joined: Wed Jun 03, 2015 11:35 am

Re: Feature Request: Ed25519 SSH keys

Fri Mar 31, 2023 2:57 pm

What's new in 7.9beta4 (2023-Mar-23 15:01):
*) ssh - added Ed25519 host key support;
Top
tangent
Forum Veteran
Forum Veteran
Posts: 949
Joined: Thu Jul 01, 2021 3:15 pm

Re: Feature Request: Ed25519 SSH keys

Fri Mar 31, 2023 5:34 pm

That's only the host key part. It doesn't let you set up pre-shared ed25519 keys per user.

One hopes the latter piece is coming later in the 7.9 beta process.
Top
theprojectgroup
Frequent Visitor
Frequent Visitor
Posts: 99
Joined: Tue Feb 21, 2017 11:40 pm

Re: Feature Request: Ed25519 SSH keys

Sat Apr 01, 2023 9:11 pm

+1. Please, still unsupported in 2023?
Top
laca77
just joined
Posts: 14
Joined: Wed Jun 03, 2015 11:35 am

Re: Feature Request: Ed25519 SSH keys

Thu Apr 06, 2023 12:35 pm

7.9rc2 changelog:
Changes in this release:

*) ssh - added support for Ed25519 key export and import in PKCS8 format;
Top
User avatar
eworm
Forum Guru
Forum Guru
Posts: 1034
Joined: Wed Oct 22, 2014 9:23 am
Location:Oberhausen, Germany
Contact:

Re: Feature Request: Ed25519 SSH keys

Thu Apr 06, 2023 5:37 pm

This is still just host key support, not public key authentication.
Top
rotor
just joined
Posts: 2
Joined: Mon Jan 23, 2023 10:56 pm

Re: Feature Request: Ed25519 SSH keys

Wed May 03, 2023 12:58 pm

Confirmed it still doesn't import on 7.9.
Code:Select all
[admin@MikroTik] > /user/ssh-keys/import public-key-file=id_ed25519.pub user=admin unable to load key file (wrong format or bad passphrase)! [admin@MikroTik] > /system/resource/print uptime: 13h5m31s version: 7.9 (stable) build-time: May/02/2023 05:35:06 factory-software: 6.46.3 free-memory: 201.8MiB total-memory: 256.0MiB cpu: MIPS 1004Kc V2.15 cpu-count: 4 cpu-frequency: 880MHz cpu-load: 4% free-hdd-space: 4208.0KiB total-hdd-space: 16.0MiB write-sect-since-reboot: 2563 write-sect-total: 375345 architecture-name: mmips board-name: hEX platform: MikroTik [admin@MikroTik] >
Top
infabo
Member
Member
Posts: 340
Joined: Thu Nov 12, 2020 12:07 pm

Re: Feature Request: Ed25519 SSH keys

Wed May 10, 2023 2:41 pm

And now I'd like to use my ED25519-SK token for public key authentication. That's still not possible in ROS 7.9
Top
mantouboji
newbie
Posts: 27
Joined: 我2022年8月1日21点

Re: Feature Request: Ed25519 SSH keys

我2023年5月29日22点

how long should we wait ?
Top
User avatar
rextended
Forum Guru
Forum Guru
Posts: 11472
Joined: Tue Feb 25, 2014 12:49 pm
Location:Italy
Contact:

Re: Feature Request: Ed25519 SSH keys

Mon May 29, 2023 11:26 am

how long should we wait ?
Until it's finished.
Top
lucidnx
just joined
Posts: 14
Joined: Tue Jan 08, 2019 10:17 am

Re: Feature Request: Ed25519 SSH keys

Sat Jun 10, 2023 4:59 pm

I would love ed25519-sk support as well since I am using yubikeys.
Top
mantouboji
newbie
Posts: 27
Joined: 我2022年8月1日21点

Re: Feature Request: Ed25519 SSH keys

Wed Jul 19, 2023 12:04 pm

How about the progress ?
Top
User avatar
eworm
Forum Guru
Forum Guru
Posts: 1034
Joined: Wed Oct 22, 2014 9:23 am
Location:Oberhausen, Germany
Contact:

Re: Feature Request: Ed25519 SSH keys

Thu Aug 17, 2023 1:02 pm

Available now in 7.12beta1!
Top

Who is online

Users browsing this forum:Ahrefs [Bot],Bing [Bot],detniels,kingstjam,Ratatouille,Semrush [Bot]and 37 guests