<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cannot disable weak SSH ciphers in Gaia Embedded in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Cannot-disable-weak-SSH-ciphers-in-Gaia-Embedded/m-p/170645#M8204</link>
    <description>&lt;P&gt;The platforms in question are End of Sale as of 2020.&lt;BR /&gt;In this case "support" means with existing functionality, not new functionality.&lt;BR /&gt;Refer to our&amp;nbsp;&lt;A href="https://www.checkpoint.com/support-services/support-life-cycle-policy/" target="_self"&gt;Appliance Support Timeline&lt;/A&gt;&amp;nbsp;for details.&lt;/P&gt;
&lt;P&gt;Dropbear (used in R77.20.xx for ssh/sshd) doesn't provide a mechanism to change the ciphers used.&lt;BR /&gt;That means to provide this functionality, either Dropbear needs modification or it needs to be replaced with something else (like OpenSSH).&lt;BR /&gt;Further, the appliances that run R77.20.xx cannot run R8x code due to hardware limitations.&lt;BR /&gt;This means additional development would be required to support this in R77.20.xx.&lt;BR /&gt;As the affected appliances are End of Sale, this is not currently planned and would require an RFE with your local Check Point office.&lt;/P&gt;</description>
    <pubDate>Tue, 07 Feb 2023 20:21:40 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2023-02-07T20:21:40Z</dc:date>
    <item>
      <title>Cannot disable weak SSH ciphers in Gaia Embedded</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Cannot-disable-weak-SSH-ciphers-in-Gaia-Embedded/m-p/170618#M8200</link>
      <description>&lt;P&gt;Hi community,&lt;/P&gt;&lt;P&gt;I'd like to disable some (considered weaker) ciphers on SMB appliances, namely on SSH service, like 3DES, SHA1, etc.&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;After researching through knowledge base and checkmates community, I could only find a solution that&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;only&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;applies to standard Gaia OS - and not Embedded Gaia.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;So I decided to open a case in TAC, who analyzed it and answered that I should submit an RFE for this. I'm kind of surprised that a security concern/issue is getting from Check Point the same kind of attention as any other feature....&lt;/P&gt;&lt;P&gt;However does anyone was able to perform successfully any "unofficial" tweak to accomplish this?&lt;/P&gt;&lt;P&gt;I'll perform a RFE anyway...&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Pedro&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Feb 2023 16:44:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Cannot-disable-weak-SSH-ciphers-in-Gaia-Embedded/m-p/170618#M8200</guid>
      <dc:creator>Pedro_Boavida</dc:creator>
      <dc:date>2023-02-07T16:44:21Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot disable weak SSH ciphers in Gaia Embedded</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Cannot-disable-weak-SSH-ciphers-in-Gaia-Embedded/m-p/170620#M8201</link>
      <description>&lt;P&gt;The Gaia OS solution for this (cipher_util) is available on R81.10.05 in Expert Mode.&lt;BR /&gt;Refer to the docs here:&amp;nbsp;&lt;A href="https://sc1.checkpoint.com/documents/SMB_R81.10.X/CLI/EN/Content/Topics/cipher_util.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/SMB_R81.10.X/CLI/EN/Content/Topics/cipher_util.htm&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;For SSH, R81.10.05 appears to be using OpenSSH and reads its configuration file from /pfrm2.0/etc/sshd_config&lt;BR /&gt;Presumably,&amp;nbsp; this is where you would make changes to the allowable SSH ciphers.&lt;BR /&gt;In past releases (certainly in R77.20.xx), Dropbear is used, which doesn't provide a mechanism for changing the ciphers.&lt;/P&gt;</description>
      <pubDate>Tue, 07 Feb 2023 16:53:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Cannot-disable-weak-SSH-ciphers-in-Gaia-Embedded/m-p/170620#M8201</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-02-07T16:53:56Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot disable weak SSH ciphers in Gaia Embedded</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Cannot-disable-weak-SSH-ciphers-in-Gaia-Embedded/m-p/170626#M8202</link>
      <description>&lt;P&gt;Thanks Dameon,&lt;/P&gt;&lt;P&gt;Actually I'm talking about past releases, however version R77.20.xx is still supported until 2025.&lt;/P&gt;&lt;P&gt;This should not be a constraint.&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Feb 2023 17:34:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Cannot-disable-weak-SSH-ciphers-in-Gaia-Embedded/m-p/170626#M8202</guid>
      <dc:creator>Pedro_Boavida</dc:creator>
      <dc:date>2023-02-07T17:34:22Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot disable weak SSH ciphers in Gaia Embedded</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Cannot-disable-weak-SSH-ciphers-in-Gaia-Embedded/m-p/170645#M8204</link>
      <description>&lt;P&gt;The platforms in question are End of Sale as of 2020.&lt;BR /&gt;In this case "support" means with existing functionality, not new functionality.&lt;BR /&gt;Refer to our&amp;nbsp;&lt;A href="https://www.checkpoint.com/support-services/support-life-cycle-policy/" target="_self"&gt;Appliance Support Timeline&lt;/A&gt;&amp;nbsp;for details.&lt;/P&gt;
&lt;P&gt;Dropbear (used in R77.20.xx for ssh/sshd) doesn't provide a mechanism to change the ciphers used.&lt;BR /&gt;That means to provide this functionality, either Dropbear needs modification or it needs to be replaced with something else (like OpenSSH).&lt;BR /&gt;Further, the appliances that run R77.20.xx cannot run R8x code due to hardware limitations.&lt;BR /&gt;This means additional development would be required to support this in R77.20.xx.&lt;BR /&gt;As the affected appliances are End of Sale, this is not currently planned and would require an RFE with your local Check Point office.&lt;/P&gt;</description>
      <pubDate>Tue, 07 Feb 2023 20:21:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Cannot-disable-weak-SSH-ciphers-in-Gaia-Embedded/m-p/170645#M8204</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-02-07T20:21:40Z</dc:date>
    </item>
  </channel>
</rss>

