You are reading a single comment by @itsbruce and its replies. Click here to read the full conversation.
  • Cool, thanks Bruce. That's reassuring. Will look further into converting our ssh keys.

  • Well, do you have a reason to think GoAnywhere is storing those keys in an insecure manner? That would be an issue.

  • No, the application is installed on-prem so GoAnywhere aren't storing the keys themselves. My main concern honestly is the seeming lack of know-how at their end about how their own product works. The Sales Engineer we're dealing with said verbatim:

    I confirmed GoAnywhere creates PKCS#8 keys when it exports, so probably what it wants on import, fair to say. I am suspecting those are in PKCS#5 format commonly used by FileZilla and many older clients.

    Maybe I'm being too harsh, but I don't love the 'probably' in this.

About

Avatar for itsbruce @itsbruce started