<@U070SQMD1> - I might have found a Lucee 5.4 regr...
# lucee
b
@zackster - I might have found a Lucee 5.4 regression issue... With 5.3.10.120 I am able to connect to a secure ftp server but with 5.4.0.80 (and 5.4.1.1-snapshot) the connection fails with the error "com.jcraft.jsch.JSchAlgoNegoFailException: Algorithm negotiation fail: algorithmName="server_host_key" jschProposal="ecdsa-sha2-nistp256,ecdsa-sha2-nistp384,ecdsa-sha2-nistp521,rsa-sha2-512,rsa-sha2-256" serverProposal="ssh-dss"
Windows 10 (10.0) 64bit - Java 11.0.7 (AdoptOpenJDK) 64bit - Tomcat Apache Tomcat/9.0.35
z
5.4 and 6.0 uses a modern fork of jsch https://github.com/lucee/Lucee/blob/5.4/core/src/main/java/META-INF/MANIFEST.MF#L354 com.github.mwiede.jsch;bundle-version=0.2.8, 5.3 uses an more ancient version org.lucee.jsch;bundle-version=0.1.55,
see anything in that repo issues? https://github.com/mwiede/jsch
b
Without really understanding all of that I'm guessing we need to do something from these recommendations...
We are connecting to client FTP servers so have no control over the key types they support.
z
a
We've just had this upgrading to 5.4.1.8. Is there a ticket in Lucee's Jira tracking a non-bodge fix for this? NB: not on Windows. Using Lucee's 5.4.1.8-nginx docker image. Does this break SFTP for everyone using 5.4+? Or some idiosyncrasy of the connection we're making? If I try to guess what this is actually on about:
Copy code
Algorithm negotiation fail: algorithmName="server_host_key" jschProposal="ecdsa-sha2-nistp256,ecdsa-sha2-nistp384,ecdsa-sha2-nistp521,rsa-sha2-512,rsa-sha2-256" serverProposal="ssh-rsa"
Is it saying our end is going "we can use these algorithms" and the remove FTP server is saying "yeah but I need you to use this one"? And jsch is going no can do?
👍 1
z
the sftp server you are connecting to is simply using an old protocol which is considered by jsch insecure and not supported, allowing an older algo via a system property isn't a bodge
the only workaround for lucee would to be enable older protocols by default via exactly the same mechanism
a
Sure. The software shouldn't break like this between 5.3 and 5.4. And should be documented as such for 5.x to 6.x.
Might not have been the best move to switch between lib maintainers in a minor release? Was this change of the jsch lib across a major version release, or undocumented? Or due to you shifting libs?
z
the old library was no longer maintained and didn't support modern Algorithms
5.4 was announced as a changing underlying libaries which were no longer supportable, hence jsch and s3 changes
I have updated the ticket ttile to help, a simple search of jira provided the workaround (before I updated the title too) https://luceeserver.atlassian.net/issues/?jql=text%20~%20%22Algorithm%20negotiation%20fail*%22
⭐ 1
a
Nice. TBH I think with 5.4 you should bake that change in, given it's hit ppl. It's no help to me now - my tomorrow is now derailed sorting this stuff out on our end - but to save others wasting their time.