<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic SSH key exchange algorithms in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SSH-key-exchange-algorithms/m-p/92645#M10780</link>
    <description>&lt;P&gt;We're needing to tighten up our SSH settings if possible.&lt;/P&gt;&lt;P&gt;These two lines have been set in /etc/ssh/sshd_config and are producing the expected results.&lt;/P&gt;&lt;P&gt;Ciphers aes256-ctr,aes192-ctr,aes128-ctr&lt;BR /&gt;MACs hmac-sha1&lt;/P&gt;&lt;P&gt;However, trying to set the key exchange algorithms with this does not work:&lt;/P&gt;&lt;P&gt;KexAlgorithms diffie-hellman-group14-sha1&lt;/P&gt;&lt;P&gt;I've tried various combos; the actual goal is to disable this one, as it shows up as available: diffie-hellman-group-exchange-sha1&lt;/P&gt;&lt;P&gt;| ssh2-enum-algos:&lt;BR /&gt;| kex_algorithms: (2)&lt;BR /&gt;| diffie-hellman-group-exchange-sha1&lt;BR /&gt;| diffie-hellman-group14-sha1&lt;/P&gt;&lt;P&gt;Regardless, the result of trying to set KexAlgorithms in any way is:&lt;/P&gt;&lt;P&gt;Starting sshd: /etc/ssh/sshd_config: line 89: Bad configuration option: KexAlgorithms&lt;BR /&gt;/etc/ssh/sshd_config: terminating, 1 bad configuration options&lt;BR /&gt;[FAILED]&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I thought CP uses standard OpenSSH, so in theory that option should work correct?&lt;/P&gt;&lt;P&gt;We're on R80.10 if that matters. Anyone have any ideas? Thanks!&lt;/P&gt;</description>
    <pubDate>Tue, 28 Jul 2020 15:38:06 GMT</pubDate>
    <dc:creator>cvega-nrel</dc:creator>
    <dc:date>2020-07-28T15:38:06Z</dc:date>
    <item>
      <title>SSH key exchange algorithms</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SSH-key-exchange-algorithms/m-p/92645#M10780</link>
      <description>&lt;P&gt;We're needing to tighten up our SSH settings if possible.&lt;/P&gt;&lt;P&gt;These two lines have been set in /etc/ssh/sshd_config and are producing the expected results.&lt;/P&gt;&lt;P&gt;Ciphers aes256-ctr,aes192-ctr,aes128-ctr&lt;BR /&gt;MACs hmac-sha1&lt;/P&gt;&lt;P&gt;However, trying to set the key exchange algorithms with this does not work:&lt;/P&gt;&lt;P&gt;KexAlgorithms diffie-hellman-group14-sha1&lt;/P&gt;&lt;P&gt;I've tried various combos; the actual goal is to disable this one, as it shows up as available: diffie-hellman-group-exchange-sha1&lt;/P&gt;&lt;P&gt;| ssh2-enum-algos:&lt;BR /&gt;| kex_algorithms: (2)&lt;BR /&gt;| diffie-hellman-group-exchange-sha1&lt;BR /&gt;| diffie-hellman-group14-sha1&lt;/P&gt;&lt;P&gt;Regardless, the result of trying to set KexAlgorithms in any way is:&lt;/P&gt;&lt;P&gt;Starting sshd: /etc/ssh/sshd_config: line 89: Bad configuration option: KexAlgorithms&lt;BR /&gt;/etc/ssh/sshd_config: terminating, 1 bad configuration options&lt;BR /&gt;[FAILED]&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I thought CP uses standard OpenSSH, so in theory that option should work correct?&lt;/P&gt;&lt;P&gt;We're on R80.10 if that matters. Anyone have any ideas? Thanks!&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jul 2020 15:38:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SSH-key-exchange-algorithms/m-p/92645#M10780</guid>
      <dc:creator>cvega-nrel</dc:creator>
      <dc:date>2020-07-28T15:38:06Z</dc:date>
    </item>
    <item>
      <title>Re: SSH key exchange algorithms</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SSH-key-exchange-algorithms/m-p/92657#M10781</link>
      <description>&lt;P&gt;R80.10 is using an older version of OpenSSH which may not support those options.&lt;BR /&gt;This is required due to the older Linux kernel version in R80.10.&lt;BR /&gt;When we updated the Linux kernel in R80.40, we also updated OpenSSH and many other userspace tools.&lt;/P&gt;
&lt;P&gt;It is not likely we will update OpenSSH in versions prior to R80.40.&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jul 2020 18:18:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SSH-key-exchange-algorithms/m-p/92657#M10781</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-07-28T18:18:11Z</dc:date>
    </item>
    <item>
      <title>Re: SSH key exchange algorithms</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SSH-key-exchange-algorithms/m-p/112271#M15576</link>
      <description>&lt;P&gt;Did you find a solution to this ?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 02 Mar 2021 13:01:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SSH-key-exchange-algorithms/m-p/112271#M15576</guid>
      <dc:creator>LostBoY</dc:creator>
      <dc:date>2021-03-02T13:01:42Z</dc:date>
    </item>
    <item>
      <title>Re: SSH key exchange algorithms</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SSH-key-exchange-algorithms/m-p/112291#M15584</link>
      <description>&lt;P&gt;SecurePlatform and GAiA versions with the 2.6 kernel (I think all firewalls from R65 through R80.40 and all managements from R65 through R80.30) have OpenSSH&amp;nbsp;&lt;SPAN&gt;4.3p2. That version is too old to support configurable key exchange protocols. You have to upgrade to a newer OS version (R80.40 or R81) to get the newer kernel (3.10) and newer OpenSSH (now 7.8p1). Once you have upgraded, KexAlgorithms should be a valid option in the sshd_config.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 02 Mar 2021 15:36:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SSH-key-exchange-algorithms/m-p/112291#M15584</guid>
      <dc:creator>Bob_Zimmerman</dc:creator>
      <dc:date>2021-03-02T15:36:32Z</dc:date>
    </item>
  </channel>
</rss>

