Repository navigation
Resolve Incompatibility with MobaXterm and Problem with DisableMTAES - #161
Merged
Merged
Conversation
rapier1
commented
Sep 16, 2026
Owner
- DisableMATES wasn't working correctly, On rekeys the flag to disable the parallel AES-CTR cipher wasn't being used which meant that it would be started on a rekey. Likely had no error reports because of the 32GB rekey limit.
- MobaXterm uses a SFTP modules for the GUI that would lead to the seqnr getting out of sync on rekeys. This led to a corrupted MAC on input immediately after a rekey. Created a compat flag for this to push the kex-strict marker to MobaXterm (and the sftp module they use from n-software called SecureBlackBox) on every rekey.
- Crank version number to 18.11.1
Turns out that the guard against using AES-CTR-MT only applied on the initial post-auth rekey and was never checked again for subsequent rekeys. This was never fully tested until trying to resolve an issue with MobaXterm (using SecureBlackbox 9). This patch shoudl resolve this issue.
MobaXterm uses SecureBlackBox for their SFTP GUI. The version they are using expects to see a kex-strict marker for each rekey KEXINIT. If it doesn't see that it won't reset the sequence number while OpenSSH will reset the seqnr. This leads to the seqnr being out of sync and generates a corrupt MAC on input error. I do not knwo if this applies to all versions of SBB but the banner in the server debug log lists it as SecureBlackBox.9 but that's an arbitrary string. This means that the fix is to create a compat flag for all matches on SecureBlackBox. If the flag is present then we issue a kex-strict marker on every rekey/KEXINIT. This forces the remote side to reset their seqnr and everything ends up being in sync again.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.