Page MenuHomeFreeBSD

EC2: Disable RSA host key generation for sshd
ClosedPublic

Authored by cperciva on Sep 11 2024, 5:09 AM.
Tags
None
Referenced Files
Unknown Object (File)
Tue, Oct 29, 2:47 PM
Unknown Object (File)
Tue, Oct 29, 4:43 AM
Unknown Object (File)
Thu, Oct 17, 11:51 AM
Unknown Object (File)
Oct 9 2024, 3:56 AM
Unknown Object (File)
Oct 2 2024, 7:57 PM
Unknown Object (File)
Sep 19 2024, 11:43 AM
Unknown Object (File)
Sep 17 2024, 12:07 AM
Unknown Object (File)
Sep 13 2024, 4:20 AM
Subscribers

Details

Summary

These are largely obsolete, and generating them is responsible for
over 10% of the total boot time of EC2 instances.

Sponsored by: Amazon

Diff Detail

Repository
rG FreeBSD src repository
Lint
Lint Not Applicable
Unit
Tests Not Applicable

Event Timeline

Perhaps just do this globally?

Perhaps just do this globally?

I considered that, but thought maybe better to wait for 16 for that. After all, for physical servers, the amount of time spent generating the RSA host key is small compared to the time spent installing FreeBSD; it only matters in the context of "pre-installed" FreeBSD.

This revision was not accepted when it landed; it landed in state Needs Review.Sep 18 2024, 6:48 AM
This revision was automatically updated to reflect the committed changes.