summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorChristian Breunig <christian@breunig.cc>2025-12-14 18:58:00 +0100
committerChristian Breunig <christian@breunig.cc>2025-12-14 18:58:00 +0100
commitef13a6319a21c8030301aeebbeabf5148adb994c (patch)
treec7e2fe4293ecfc55606d3020c7f697a178af1109
parent812eea9a3a20afebc20b374a30ceac7f0d87c9b4 (diff)
downloadvyos-1x-ef13a6319a21c8030301aeebbeabf5148adb994c.tar.gz
vyos-1x-ef13a6319a21c8030301aeebbeabf5148adb994c.zip
ssh: T8098: rename "ciphers" CLI node to "cipher"
Follow VyOS CLI best practices for using singular whenever possible to build a CLI node. As we introduce a new migration 2 -> 3 for SSH we can correct this minor detail.
-rw-r--r--data/templates/ssh/sshd_config.j26
-rw-r--r--interface-definitions/service_ssh.xml.in2
-rw-r--r--smoketest/configs/assert/basic-vyos8
-rwxr-xr-xsmoketest/scripts/cli/test_service_ssh.py2
-rw-r--r--src/migration-scripts/ssh/2-to-320
5 files changed, 23 insertions, 15 deletions
diff --git a/data/templates/ssh/sshd_config.j2 b/data/templates/ssh/sshd_config.j2
index 1315bf2cb..d5d155340 100644
--- a/data/templates/ssh/sshd_config.j2
+++ b/data/templates/ssh/sshd_config.j2
@@ -57,9 +57,9 @@ ListenAddress {{ address }}
{% endfor %}
{% endif %}
-{% if ciphers is vyos_defined %}
-# Specifies the ciphers allowed for protocol version 2
-Ciphers {{ ciphers | join(',') }}
+{% if cipher is vyos_defined %}
+# Specifies allowed ciphers for protocol version 2
+Ciphers {{ cipher | join(',') }}
{% endif %}
{% if hostkey_algorithm is vyos_defined %}
diff --git a/interface-definitions/service_ssh.xml.in b/interface-definitions/service_ssh.xml.in
index 4d10de646..9fd9e32c3 100644
--- a/interface-definitions/service_ssh.xml.in
+++ b/interface-definitions/service_ssh.xml.in
@@ -36,7 +36,7 @@
</node>
</children>
</node>
- <leafNode name="ciphers">
+ <leafNode name="cipher">
<properties>
<help>Allowed ciphers</help>
<completionHelp>
diff --git a/smoketest/configs/assert/basic-vyos b/smoketest/configs/assert/basic-vyos
index 20363b77f..48ba51b21 100644
--- a/smoketest/configs/assert/basic-vyos
+++ b/smoketest/configs/assert/basic-vyos
@@ -81,10 +81,10 @@ set service dns forwarding allow-from '192.168.0.0/16'
set service dns forwarding cache-size '10000'
set service dns forwarding dnssec 'off'
set service dns forwarding listen-address '192.168.0.1'
-set service ssh ciphers 'aes128-ctr'
-set service ssh ciphers 'aes192-ctr'
-set service ssh ciphers 'aes256-ctr'
-set service ssh ciphers 'chacha20-poly1305@openssh.com'
+set service ssh cipher 'aes128-ctr'
+set service ssh cipher 'aes192-ctr'
+set service ssh cipher 'aes256-ctr'
+set service ssh cipher 'chacha20-poly1305@openssh.com'
set service ssh key-exchange 'curve25519-sha256@libssh.org'
set service ssh key-exchange 'diffie-hellman-group1-sha1'
set service ssh key-exchange 'diffie-hellman-group-exchange-sha1'
diff --git a/smoketest/scripts/cli/test_service_ssh.py b/smoketest/scripts/cli/test_service_ssh.py
index 6935464a7..4ef3dd51d 100755
--- a/smoketest/scripts/cli/test_service_ssh.py
+++ b/smoketest/scripts/cli/test_service_ssh.py
@@ -378,7 +378,7 @@ class TestServiceSSH(VyOSUnitTestSHIM.TestCase):
rekey_data = '1024'
for cipher in ciphers:
- self.cli_set(base_path + ['ciphers', cipher])
+ self.cli_set(base_path + ['cipher', cipher])
for host_key in host_key_algs:
self.cli_set(base_path + ['hostkey-algorithm', host_key])
for kex in kexes:
diff --git a/src/migration-scripts/ssh/2-to-3 b/src/migration-scripts/ssh/2-to-3
index e18a6aa05..ac9f7156c 100644
--- a/src/migration-scripts/ssh/2-to-3
+++ b/src/migration-scripts/ssh/2-to-3
@@ -14,18 +14,26 @@
# along with this library. If not, see <http://www.gnu.org/licenses/>.
# T8098: rijndael-cbc@lysator.liu.se was removed in OpenSSH 6.7 which is used
-# starting with VyOS 1.4
+# starting with VyOS 1.4. Also rename "ciphers" -> "cipher" to follow our
+# CLI guidelines to use singular when possible
from vyos.configtree import ConfigTree
base = ['service', 'ssh']
+old_path = base + ['ciphers']
+new_path = base + ['cipher']
+
def migrate(config: ConfigTree) -> None:
- if not config.exists(base + ['ciphers']):
+ if not config.exists(base):
# Nothing to do
return
- deprecated_cipher = 'rijndael-cbc@lysator.liu.se'
- for cipher in config.return_values(base + ['ciphers']):
- if cipher == deprecated_cipher:
- config.delete_value(base + ['ciphers'], value=deprecated_cipher)
+ if config.exists(old_path):
+ config.rename(old_path, new_path[-1])
+
+ if config.exists(new_path):
+ deprecated_cipher = 'rijndael-cbc@lysator.liu.se'
+ for cipher in config.return_values(new_path):
+ if cipher == deprecated_cipher:
+ config.delete_value(new_path, value=deprecated_cipher)