<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SSH Weak Key Exchange Algorithms Enabled in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SSH-Weak-Key-Exchange-Algorithms-Enabled/m-p/220265#M42143</link>
    <description>&lt;P&gt;Please review: &lt;A href="https://support.checkpoint.com/results/sk/sk172189" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk172189&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 10 Jul 2024 17:16:41 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2024-07-10T17:16:41Z</dc:date>
    <item>
      <title>SSH Weak Key Exchange Algorithms Enabled</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SSH-Weak-Key-Exchange-Algorithms-Enabled/m-p/220045#M42103</link>
      <description>&lt;P&gt;Hi Guys,&lt;/P&gt;&lt;P&gt;I got this finding from external company doing scan of my network. I updated checkpoint to version R81.10 take 335. I'm wondering if this update will solve the problem itself or I need to do something more to it. I got something like this from them.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;DIV&gt;&lt;STRONG&gt;The remote SSH server [IP] is configured to allow key exchange algorithms, which are considered weak.&lt;/STRONG&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;STRONG&gt;This is based on the IETF draft document Key Exchange (KEX) Method Updates and Recommendations for Secure Shell (SSH) draft-ietf-curdle-ssh-kex-sha2-20. Section 4 lists guidance on key exchange algorithms that SHOULD NOT and MUST NOT be enabled. This includes:&lt;/STRONG&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;STRONG&gt;•&amp;nbsp;Diffie-hellman-group-exchange-sha1&lt;/STRONG&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;STRONG&gt;•&amp;nbsp;Diffie-hellman-group1-sha1&lt;/STRONG&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;STRONG&gt;•&amp;nbsp;gss-gex-sha1-*&lt;/STRONG&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;STRONG&gt;•&amp;nbsp;gss-group1-sha1-*&lt;/STRONG&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;STRONG&gt;•&amp;nbsp;gss-group14-sha1-*&lt;/STRONG&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;STRONG&gt;•&amp;nbsp;rsa1024-sha1&lt;/STRONG&gt;&lt;/DIV&gt;</description>
      <pubDate>Tue, 09 Jul 2024 07:16:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SSH-Weak-Key-Exchange-Algorithms-Enabled/m-p/220045#M42103</guid>
      <dc:creator>Failte_Peter</dc:creator>
      <dc:date>2024-07-09T07:16:07Z</dc:date>
    </item>
    <item>
      <title>Re: SSH Weak Key Exchange Algorithms Enabled</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SSH-Weak-Key-Exchange-Algorithms-Enabled/m-p/220265#M42143</link>
      <description>&lt;P&gt;Please review: &lt;A href="https://support.checkpoint.com/results/sk/sk172189" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk172189&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jul 2024 17:16:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SSH-Weak-Key-Exchange-Algorithms-Enabled/m-p/220265#M42143</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-07-10T17:16:41Z</dc:date>
    </item>
  </channel>
</rss>

