<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SSH Weak Key Exchange Algorithms Enabled in Catalyst 3850 48 Port in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ssh-weak-key-exchange-algorithms-enabled-in-catalyst-3850-48/m-p/5210033#M1116637</link>
    <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1651040"&gt;@Minato&lt;/a&gt; you may need to upgrade your IOS-XE version to support the latest crypto. Use the following commands:-&lt;/P&gt;
&lt;PRE&gt;ip ssh server algorithm mac hmac-sha2-512 hmac-sha2-256
ip ssh server algorithm encryption aes256-gcm aes256-ctr aes192-ctr aes128-gcm 
ip ssh server algorithm kex ecdh-sha2-nistp384 ecdh-sha2-nistp256&lt;/PRE&gt;
&lt;P&gt;This post covers securing IOS-XE SSH in more detail - &lt;A href="https://integrate.uk.com/securing-ios-xe-ssh/" target="_blank"&gt;https://integrate.uk.com/securing-ios-xe-ssh/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 17 Oct 2024 06:44:56 GMT</pubDate>
    <dc:creator>Rob Ingram</dc:creator>
    <dc:date>2024-10-17T06:44:56Z</dc:date>
    <item>
      <title>SSH Weak Key Exchange Algorithms Enabled in Catalyst 3850 48 Port PoE</title>
      <link>https://community.cisco.com/t5/network-security/ssh-weak-key-exchange-algorithms-enabled-in-catalyst-3850-48/m-p/5209970#M1116635</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Cisco switch Catalyst 3850 48 Port PoE - Vulnerability&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;can any one help me to fix the issue&lt;/P&gt;&lt;P&gt;test#sh ip ssh&lt;BR /&gt;SSH Enabled - version 2.0&lt;BR /&gt;Authentication methods:publickey,keyboard-interactive,password&lt;BR /&gt;Authentication Publickey Algorithms:x509v3-ssh-rsa,ssh-rsa,ecdsa-sha2-nistp256,ecdsa-sha2-nistp384,x509v3-ecdsa-sha2-nistp256,x509v3-ecdsa-sha2-nistp384,rsa-sha2-256,rsa-sha2-512&lt;BR /&gt;Hostkey Algorithms:x509v3-ssh-rsa,rsa-sha2-512,rsa-sha2-256,ssh-rsa&lt;BR /&gt;Encryption Algorithms:aes256-ctr,aes128-ctr&lt;BR /&gt;MAC Algorithms:hmac-sha1&lt;BR /&gt;KEX Algorithms:ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha1,diffie-hellman-group14-sha1&lt;BR /&gt;Authentication timeout: 120 secs; Authentication retries: 3&lt;BR /&gt;Minimum expected Diffie Hellman key size : 2048 bits&lt;BR /&gt;IOS Keys in SECSH format(ssh-rsa, base64 encoded): TP-self-signed-1611723854&lt;BR /&gt;ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAAAgQDDVe73ODoAh3O6V8eWto+k4oqGyoHIr6RYQOikubUy&lt;BR /&gt;qcNg4rG38y2zd/8lBXEal4kNwN6mfVZ2XiijcFMJdkO8csLfATMQETm2Z4yLcHZQNaTTHcxWsudxbBSd&lt;BR /&gt;tXZscw4Ysg1vyah3BEx1RhJWcHagVh+xl/BJXnzy/3xcU6SXvw==&lt;BR /&gt;test#&lt;/P&gt;</description>
      <pubDate>Thu, 17 Oct 2024 04:40:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ssh-weak-key-exchange-algorithms-enabled-in-catalyst-3850-48/m-p/5209970#M1116635</guid>
      <dc:creator>Minato</dc:creator>
      <dc:date>2024-10-17T04:40:07Z</dc:date>
    </item>
    <item>
      <title>Re: SSH Weak Key Exchange Algorithms Enabled in Catalyst 3850 48 Port</title>
      <link>https://community.cisco.com/t5/network-security/ssh-weak-key-exchange-algorithms-enabled-in-catalyst-3850-48/m-p/5210033#M1116637</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1651040"&gt;@Minato&lt;/a&gt; you may need to upgrade your IOS-XE version to support the latest crypto. Use the following commands:-&lt;/P&gt;
&lt;PRE&gt;ip ssh server algorithm mac hmac-sha2-512 hmac-sha2-256
ip ssh server algorithm encryption aes256-gcm aes256-ctr aes192-ctr aes128-gcm 
ip ssh server algorithm kex ecdh-sha2-nistp384 ecdh-sha2-nistp256&lt;/PRE&gt;
&lt;P&gt;This post covers securing IOS-XE SSH in more detail - &lt;A href="https://integrate.uk.com/securing-ios-xe-ssh/" target="_blank"&gt;https://integrate.uk.com/securing-ios-xe-ssh/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 17 Oct 2024 06:44:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ssh-weak-key-exchange-algorithms-enabled-in-catalyst-3850-48/m-p/5210033#M1116637</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2024-10-17T06:44:56Z</dc:date>
    </item>
  </channel>
</rss>

