<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic SFTP cyphers in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/sftp-cyphers/m-p/3545564#M527651</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi team,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have a Customer that would like to know if we updated the SFTP cyphers since ISE 2.O, they woulf like to use aeS256-ctr and ISE 2.0 does not support it :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Times New Roman; font-size: 12pt;"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: Calibri;"&gt;&lt;EM&gt;&lt;SPAN style="color: #000000; font-size: 11pt;"&gt;Jul 21 09:43:08 lxpr540a sshd[4359]: fatal: no matching cipher found: client aes256-cbc,aes128-cbc,&lt;/SPAN&gt;&lt;SPAN style="font-size: 11pt;"&gt;&lt;A href="mailto:aes128-gcm@openssh.com"&gt;&lt;SPAN style="color: #0563c1; text-decoration: underline;"&gt;aes128-gcm@openssh.com&lt;/SPAN&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;SPAN style="color: #000000; font-size: 11pt;"&gt;,&lt;/SPAN&gt;&lt;SPAN style="font-size: 11pt;"&gt;&lt;A href="mailto:aes256-gcm@openssh.com"&gt;&lt;SPAN style="color: #0563c1; text-decoration: underline;"&gt;aes256-gcm@openssh.com&lt;/SPAN&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;SPAN style="color: #000000; font-size: 11pt;"&gt; server aes128-ctr,aes192-ctr,aes256-ctr&lt;/SPAN&gt;&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Times New Roman; font-size: 12pt;"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I found this doc but it was not updated since 2.0 : &lt;A href="https://community.cisco.com/docs/DOC-69521"&gt;ISE Security Best Practices (Hardening)&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the security team refuse to use AES-CBC due to a vulnerability "&lt;A href="http://www.isg.rhul.ac.uk/~kp/SandPfinal.pdf" title="http://www.isg.rhul.ac.uk/~kp/SandPfinal.pdf"&gt;http://www.isg.rhul.ac.uk/~kp/SandPfinal.pdf&lt;/A&gt;"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please could you tell me if we now support AES-CTR for SFTP ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;Christophe&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 14 Aug 2017 10:12:26 GMT</pubDate>
    <dc:creator>csarrazi</dc:creator>
    <dc:date>2017-08-14T10:12:26Z</dc:date>
    <item>
      <title>SFTP cyphers</title>
      <link>https://community.cisco.com/t5/network-access-control/sftp-cyphers/m-p/3545564#M527651</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi team,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have a Customer that would like to know if we updated the SFTP cyphers since ISE 2.O, they woulf like to use aeS256-ctr and ISE 2.0 does not support it :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Times New Roman; font-size: 12pt;"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: Calibri;"&gt;&lt;EM&gt;&lt;SPAN style="color: #000000; font-size: 11pt;"&gt;Jul 21 09:43:08 lxpr540a sshd[4359]: fatal: no matching cipher found: client aes256-cbc,aes128-cbc,&lt;/SPAN&gt;&lt;SPAN style="font-size: 11pt;"&gt;&lt;A href="mailto:aes128-gcm@openssh.com"&gt;&lt;SPAN style="color: #0563c1; text-decoration: underline;"&gt;aes128-gcm@openssh.com&lt;/SPAN&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;SPAN style="color: #000000; font-size: 11pt;"&gt;,&lt;/SPAN&gt;&lt;SPAN style="font-size: 11pt;"&gt;&lt;A href="mailto:aes256-gcm@openssh.com"&gt;&lt;SPAN style="color: #0563c1; text-decoration: underline;"&gt;aes256-gcm@openssh.com&lt;/SPAN&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;SPAN style="color: #000000; font-size: 11pt;"&gt; server aes128-ctr,aes192-ctr,aes256-ctr&lt;/SPAN&gt;&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Times New Roman; font-size: 12pt;"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I found this doc but it was not updated since 2.0 : &lt;A href="https://community.cisco.com/docs/DOC-69521"&gt;ISE Security Best Practices (Hardening)&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the security team refuse to use AES-CBC due to a vulnerability "&lt;A href="http://www.isg.rhul.ac.uk/~kp/SandPfinal.pdf" title="http://www.isg.rhul.ac.uk/~kp/SandPfinal.pdf"&gt;http://www.isg.rhul.ac.uk/~kp/SandPfinal.pdf&lt;/A&gt;"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please could you tell me if we now support AES-CTR for SFTP ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;Christophe&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 Aug 2017 10:12:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/sftp-cyphers/m-p/3545564#M527651</guid>
      <dc:creator>csarrazi</dc:creator>
      <dc:date>2017-08-14T10:12:26Z</dc:date>
    </item>
    <item>
      <title>Re: SFTP cyphers</title>
      <link>https://community.cisco.com/t5/network-access-control/sftp-cyphers/m-p/3545565#M527653</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There is a bug &lt;A href="https://bst.cloudapps.cisco.com/bugsearch/bug/CSCux88538"&gt;CSCux88538&lt;/A&gt; that was logged as an enhancement for ISE 1.4 to support the aes-ctr ciphers but that is still open. May be worth logging a support call with Cisco.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 Aug 2017 11:50:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/sftp-cyphers/m-p/3545565#M527653</guid>
      <dc:creator>M. Wisely</dc:creator>
      <dc:date>2017-08-14T11:50:23Z</dc:date>
    </item>
    <item>
      <title>Re: SFTP cyphers</title>
      <link>https://community.cisco.com/t5/network-access-control/sftp-cyphers/m-p/3545566#M527655</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Based on my research, we currently don't support that cipher.&amp;nbsp; We do have an enhancement request in for it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;-Tim&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 Aug 2017 14:27:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/sftp-cyphers/m-p/3545566#M527655</guid>
      <dc:creator>Timothy Abbott</dc:creator>
      <dc:date>2017-08-14T14:27:15Z</dc:date>
    </item>
    <item>
      <title>Re: SFTP cyphers</title>
      <link>https://community.cisco.com/t5/network-access-control/sftp-cyphers/m-p/3545567#M527657</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;we had same problem when we tried to setup SFTP. Then we have to change the cipher to cbc till the ISE supports .........&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 Aug 2017 17:30:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/sftp-cyphers/m-p/3545567#M527657</guid>
      <dc:creator>csco11552159</dc:creator>
      <dc:date>2017-08-14T17:30:59Z</dc:date>
    </item>
  </channel>
</rss>

