Specifying Key Exchange Algorithms For Ssh2; Specifying Public Key Algorithms For Ssh2; Specifying Encryption Algorithms For Ssh2 - HPE FlexNetwork 5510 HI Series Security Configuration Manual

Hide thumbs Also See for FlexNetwork 5510 HI Series:
Table of Contents

Advertisement

If you specify algorithms, SSH2 uses only the specified algorithms for algorithm negotiation. The
client uses the specified algorithms to initiate the negotiation, and the server uses the matching
algorithms to negotiate with the client.
If multiple algorithms of the same type are specified, the algorithm specified earlier has a higher
priority during negotiation. The specified SSH2 algorithms do not affect SSH1 sessions.

Specifying key exchange algorithms for SSH2

Step
1.
Enter system view.
2.
Specify
algorithms for SSH2.

Specifying public key algorithms for SSH2

Step
1.
Enter system view.
2.
Specify
algorithms for SSH2.

Specifying encryption algorithms for SSH2

Step
1.
Enter system view.
2.
Specify
algorithms for SSH2.
Command
system-view
key
exchange
Command
system-view
In
ssh2
{
x509v3-ecdsa-sha2-nistp384 |
x509v3-ecdsa-sha2-nistp256 }
*
public
key
In
ssh2
{
x509v3-ecdsa-sha2-nistp384 |
x509v3-ecdsa-sha2-nistp256 }
*
Command
system-view
encryption
In
non-FIPS
mode:
ssh2
algorithm
key-exchange
{ dh-group-exchange-sha1
|
dh-group1-sha1
dh-group14-sha1
ecdh-sha2-nistp256
ecdh-sha2-nistp384 } *
In
FIPS
mode:
ssh2
algorithm
key-exchange
{
dh-group14-sha1
ecdh-sha2-nistp256
ecdh-sha2-nistp384 } *
non-FIPS
mode:
algorithm
public-key
dsa
|
ecdsa
|
rsa
FIPS
mode:
algorithm
public-key
ecdsa
|
rsa
In
non-FIPS
mode:
ssh2
algorithm
cipher
{ 3des-cbc | aes128-cbc |
aes256-cbc
| des-cbc
aes128-ctr | aes192-ctr |
aes256-ctr | aes128-gcm |
352
Remarks
N/A
By default, SSH2 uses the key
exchange
|
ecdh-sha2-nistp256,
|
ecdh-sha2-nistp384,
|
dh-group-exchange-sha1,
dh-group14-sha1,
dh-group1-sha1 in descending
order of priority for algorithm
negotiation.
|
|
Remarks
N/A
|
By default, SSH2 uses the public
key
x509v3-ecdsa-sha2-nistp256,
x509v3-ecdsa-sha2-nistp384,
ecdsa,
rsa,
and
descending order of priority for
|
algorithm negotiation.
Remarks
N/A
By
default,
SSH2
encryption algorithms aes128-ctr,
aes192-ctr,
|
aes128-gcm,
aes256-gcm,
aes128-cbc,
aes256-cbc, and des-cbc
algorithms
and
algorithms
dsa
in
uses
the
aes256-ctr,
3des-cbc,
in

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents