<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SSH Weak Ciphers in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ssh-weak-ciphers/m-p/5325965#M1122479</link>
    <description>&lt;P&gt;ip ssh server algorithm mac ?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Share output of this&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If max is&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hmac-sha2-512 &amp;lt;&amp;lt;- then it routers limitations&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If routers run (Encrypt-then-MAC) ETM then run it' it more secure.&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
    <pubDate>Sun, 31 Aug 2025 21:15:05 GMT</pubDate>
    <dc:creator>MHM Cisco World</dc:creator>
    <dc:date>2025-08-31T21:15:05Z</dc:date>
    <item>
      <title>SSH Weak Ciphers</title>
      <link>https://community.cisco.com/t5/network-security/ssh-weak-ciphers/m-p/5325904#M1122474</link>
      <description>&lt;P&gt;Hello, I have two routers 1121X and 4221, and when i tried the penetration testing, i got the result below:&lt;/P&gt;&lt;P&gt;# algorithm recommendations (for Cisco IOS/PIX sshd 1.25)&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;(rec) -diffie-hellman-group-exchange-shal&amp;nbsp; &amp;nbsp; kex algorithm to remove&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;(rec) -diffie-hellman-group14-shal&amp;nbsp; &amp;nbsp; kex algorithm to remove&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;(rec) -hmac-shal&amp;nbsp; &amp;nbsp;mac algorithm to remove&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;(rec) -hmac-sha1-96&amp;nbsp; &amp;nbsp;mac algorithm to remove&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;(rec) -ssh-rsa&amp;nbsp; &amp;nbsp;key algorithm to remove&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;(rec) -hmac-sha2-256&amp;nbsp; &amp;nbsp;mac algorithm to remove&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;(rec) -hmac-sha2-512&amp;nbsp; &amp;nbsp; &amp;nbsp; mac algorithm&amp;nbsp;to&amp;nbsp;remove&lt;/P&gt;&lt;P&gt;the bold lines already solved i need to solve the last one.&lt;/P&gt;&lt;P&gt;here is some shows from my router 1121X&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Cisco IOS XE Software, Version 17.09.05a&lt;/P&gt;&lt;P&gt;Cisco IOS Software [Cupertino], ISR Software (ARMV8EL_LINUX_IOSD-UNIVERSALK9-M), Version 17.9.5a, RELEASE SOFTWARE (fc1)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;SSH Enabled - version 2.0&lt;/P&gt;&lt;P&gt;Authentication methods:publickey,keyboard-interactive,password&lt;/P&gt;&lt;P&gt;Authentication Publickey Algorithms:ssh-ed25519,ecdsa-sha2-nistp521,ecdsa-sha2-nistp384&lt;/P&gt;&lt;P&gt;Hostkey Algorithms:rsa-sha2-512&lt;/P&gt;&lt;P&gt;Encryption Algorithms:aes256-gcm,aes256-ctr&lt;/P&gt;&lt;P&gt;MAC Algorithms:hmac-sha2-512&lt;/P&gt;&lt;P&gt;KEX Algorithms:ecdh-sha2-nistp521&lt;/P&gt;&lt;P&gt;Authentication timeout: 120 secs; Authentication retries: 3&lt;/P&gt;&lt;P&gt;Minimum expected Diffie Hellman key size : 4096 bits&lt;/P&gt;&lt;P&gt;IOS Keys in SECSH format(ssh-rsa, base64 encoded): RSA-SHA2&lt;/P&gt;&lt;P&gt;Modulus Size : 4096 bits&lt;/P&gt;&lt;P&gt;ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAACAQDmK1tGkBUiKY6KJS38Y1+Si654tX+NG+HYH1HNWQv7&lt;/P&gt;&lt;P&gt;4OBmY4spkvgkM/EVkVLl+GKEvqr8XhIVGaVTiC56o3EkAQEIKxQVVaMVDlky07hPjFfRpyLIBwtirw7n&lt;/P&gt;&lt;P&gt;ngn9OsUvtUArMYbCDyEr+EAEEhmYaKUq24bBIUYU3WAQjoUAK2VxjlhM0fCwk1vBzmEo2LAtHjLKVNLS&lt;/P&gt;&lt;P&gt;Y0Mqk/VBb3F3DCYREhlXx4k7CIRHIpx8A/vq3n04jJNviMFIi37K8IK6z5ErBXQACoh68S1ziNOGPrhn&lt;/P&gt;&lt;P&gt;QjmmdPpsawhk8wxZRq9/JbF93kmVuR4WvbOML8YRqmk6nkZG2Xqz7EyU+9oovdWzZY5ZmvojO3O6XA7C&lt;/P&gt;&lt;P&gt;QvLQQ3I1U6CTkhfIaotgg3ysHbtiw6qry5nuIu4db0xVx1VKdrb0Zx/+VlHpUn/wPl40Wt4Pthulon2m&lt;/P&gt;&lt;P&gt;Br8TrKHoJcmTglcKIx4lSROkWmQY1UJEcMcACs0R+CutZLZifMEHvkQToW/2aH6dYyqWh8Uq3d0f9oov&lt;/P&gt;&lt;P&gt;ShIjKkpeM/S0lLDWPagZeijIY2pDv1hwl90W6wxB8AR1GYINo8AjH38269QmL6zQCSak8VpxKQ8dsO92&lt;/P&gt;&lt;P&gt;lFW10sxN7PLQvqXatuf1gu84/I+zsdLUwFZXHmUFHNOqkygYuvSYT7srz76PKhCvCNjWa8oh7M4F9Zti&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 31 Aug 2025 10:38:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ssh-weak-ciphers/m-p/5325904#M1122474</guid>
      <dc:creator>NMS2</dc:creator>
      <dc:date>2025-08-31T10:38:07Z</dc:date>
    </item>
    <item>
      <title>Re: SSH Weak Ciphers</title>
      <link>https://community.cisco.com/t5/network-security/ssh-weak-ciphers/m-p/5325906#M1122475</link>
      <description>&lt;P&gt;ip ssh server algorithm hostkey &amp;lt;&amp;lt;- what option available in this command?&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Sun, 31 Aug 2025 10:44:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ssh-weak-ciphers/m-p/5325906#M1122475</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-08-31T10:44:24Z</dc:date>
    </item>
    <item>
      <title>Re: SSH Weak Ciphers</title>
      <link>https://community.cisco.com/t5/network-security/ssh-weak-ciphers/m-p/5325962#M1122478</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1831550"&gt;@NMS2&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;the typical options on IOS-XE routers are the following:&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;Rtr01(config)#ip ssh server algorithm mac ?
  hmac-sha1                      HMAC-SHA1 (digest length = 160 bits,key length
                                 = 160 bits)
  hmac-sha2-256                  HMAC-SHA2-256 (digest length = 256 bits, key
                                 length = 256 bits)
  hmac-sha2-256-etm@openssh.com  HMAC-SHA2-256-ETM (digest length = 256 bits,
                                 key length = 256 bits)
  hmac-sha2-512                  HMAC-SHA2-512 (digest length = 512 bits, key
                                 length = 512 bits)
  hmac-sha2-512-etm@openssh.com  HMAC-SHA2-512-ETM (digest length = 512 bits,
                                 key length = 512 bits)

Rtr01(config)#&lt;/LI-CODE&gt;
&lt;P&gt;So which one do you want to use?&amp;nbsp;HMAC-SHA2-512-ETM?&lt;BR /&gt;Once you enabled this, you can remove HMAC-SHA2-512.&lt;/P&gt;
&lt;P&gt;HTH!&lt;/P&gt;</description>
      <pubDate>Sun, 31 Aug 2025 17:00:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ssh-weak-ciphers/m-p/5325962#M1122478</guid>
      <dc:creator>Jens Albrecht</dc:creator>
      <dc:date>2025-08-31T17:00:37Z</dc:date>
    </item>
    <item>
      <title>Re: SSH Weak Ciphers</title>
      <link>https://community.cisco.com/t5/network-security/ssh-weak-ciphers/m-p/5325965#M1122479</link>
      <description>&lt;P&gt;ip ssh server algorithm mac ?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Share output of this&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If max is&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hmac-sha2-512 &amp;lt;&amp;lt;- then it routers limitations&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If routers run (Encrypt-then-MAC) ETM then run it' it more secure.&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Sun, 31 Aug 2025 21:15:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ssh-weak-ciphers/m-p/5325965#M1122479</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-08-31T21:15:05Z</dc:date>
    </item>
    <item>
      <title>Re: SSH Weak Ciphers</title>
      <link>https://community.cisco.com/t5/network-security/ssh-weak-ciphers/m-p/5326087#M1122487</link>
      <description>&lt;P&gt;i already use hmac-sha2-512, but the &lt;SPAN&gt;penetration&lt;/SPAN&gt; test result is&amp;nbsp;&lt;BR /&gt;&lt;SPAN&gt;(rec) -hmac-sha2-512&amp;nbsp; &amp;nbsp; &amp;nbsp; mac algorithm&amp;nbsp;to&amp;nbsp;remove&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;this is the higher KEY for hmac.&lt;BR /&gt;&lt;BR /&gt;any solution&lt;/P&gt;</description>
      <pubDate>Mon, 01 Sep 2025 08:51:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ssh-weak-ciphers/m-p/5326087#M1122487</guid>
      <dc:creator>NMS2</dc:creator>
      <dc:date>2025-09-01T08:51:50Z</dc:date>
    </item>
    <item>
      <title>Re: SSH Weak Ciphers</title>
      <link>https://community.cisco.com/t5/network-security/ssh-weak-ciphers/m-p/5326088#M1122488</link>
      <description>&lt;PRE&gt;ip ssh server algorithm mac ?
  hmac-sha1                      HMAC-SHA1 (digest length = 160 bits,key length
                                 = 160 bits)
  hmac-sha2-256                  HMAC-SHA2-256 (digest length = 256 bits, key
                                 length = 256 bits)
  hmac-sha2-256-etm@openssh.com  HMAC-SHA2-256-ETM (digest length = 256 bits,
                                 key length = 256 bits)
  hmac-sha2-512                  HMAC-SHA2-512 (digest length = 512 bits, key
                                 length = 512 bits)
  hmac-sha2-512-etm@openssh.com  HMAC-SHA2-512-ETM (digest length = 512 bits,
                                 key length = 512 bits)&lt;/PRE&gt;</description>
      <pubDate>Mon, 01 Sep 2025 08:53:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ssh-weak-ciphers/m-p/5326088#M1122488</guid>
      <dc:creator>NMS2</dc:creator>
      <dc:date>2025-09-01T08:53:01Z</dc:date>
    </item>
    <item>
      <title>Re: SSH Weak Ciphers</title>
      <link>https://community.cisco.com/t5/network-security/ssh-weak-ciphers/m-p/5326114#M1122489</link>
      <description>&lt;PRE&gt;hmac-sha2-512-etm@openssh.com&lt;/PRE&gt;
&lt;P&gt;Use this&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 01 Sep 2025 10:09:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ssh-weak-ciphers/m-p/5326114#M1122489</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-09-01T10:09:17Z</dc:date>
    </item>
    <item>
      <title>Re: SSH Weak Ciphers</title>
      <link>https://community.cisco.com/t5/network-security/ssh-weak-ciphers/m-p/5326181#M1122497</link>
      <description>&lt;P&gt;it has the same&amp;nbsp;digest length, so the problem will still exist.&lt;/P&gt;</description>
      <pubDate>Mon, 01 Sep 2025 13:24:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ssh-weak-ciphers/m-p/5326181#M1122497</guid>
      <dc:creator>NMS2</dc:creator>
      <dc:date>2025-09-01T13:24:48Z</dc:date>
    </item>
    <item>
      <title>Re: SSH Weak Ciphers</title>
      <link>https://community.cisco.com/t5/network-security/ssh-weak-ciphers/m-p/5326183#M1122498</link>
      <description>&lt;P&gt;the test result need to remove hmac-sha2-512 to a large key, i can't find in my router any lagre key, the two keys with ETM has the same&amp;nbsp;digest length&lt;/P&gt;</description>
      <pubDate>Mon, 01 Sep 2025 13:27:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ssh-weak-ciphers/m-p/5326183#M1122498</guid>
      <dc:creator>NMS2</dc:creator>
      <dc:date>2025-09-01T13:27:44Z</dc:date>
    </item>
    <item>
      <title>Re: SSH Weak Ciphers</title>
      <link>https://community.cisco.com/t5/network-security/ssh-weak-ciphers/m-p/5326184#M1122499</link>
      <description>&lt;P&gt;It true it have same digest 512 but it encrypt first so it more strong.&lt;/P&gt;
&lt;P&gt;Use it and let test decided it weak or not&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Mon, 01 Sep 2025 13:27:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ssh-weak-ciphers/m-p/5326184#M1122499</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-09-01T13:27:53Z</dc:date>
    </item>
    <item>
      <title>Re: SSH Weak Ciphers</title>
      <link>https://community.cisco.com/t5/network-security/ssh-weak-ciphers/m-p/5326216#M1122501</link>
      <description>&lt;P&gt;What's the problem with&amp;nbsp;HMAC-SHA2-512-ETM?&lt;/P&gt;
&lt;P&gt;This algorithm is considered secure as of today and is recommended for use in SSH and other cryptographic protocols that require strong message authentication codes (MACs).&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The ETM (Encrypt-then-MAC) construction further hardens the protocol against certain exploits, such as padding oracle attacks and length extension attacks.&lt;/P&gt;
&lt;P&gt;So what are your looking for?&lt;/P&gt;
&lt;P&gt;SHA3 algorithms? AEAD ciphers? Quantum-resistant encryption?&lt;/P&gt;
&lt;P&gt;The routers you are using are pretty old and the 4221 already reached EOL so Cisco will not provide any new software version for this platform. These old hardware platforms simply do not support anything beyond what is offered now.&lt;/P&gt;
&lt;P&gt;The solution is simple.&lt;/P&gt;
&lt;P&gt;Scrap your routers and buy the new &lt;A href="https://www.cisco.com/site/us/en/products/networking/sdwan-routers/8000-secure-routers/index.html" target="_self"&gt;Cisco &lt;STRONG&gt;Secure&lt;/STRONG&gt; Series routers&lt;/A&gt; that have just been launched a few months ago.&lt;/P&gt;
&lt;P&gt;These routers have new hardware that is build to support future-proof branch security with advanced, quantum-resistant encryption.&lt;/P&gt;
&lt;P&gt;The&amp;nbsp;Cisco 8100 Series &lt;STRONG&gt;Secure&lt;/STRONG&gt; Routers Data Sheet can be found here:&lt;BR /&gt;&lt;A href="https://www.cisco.com/site/us/en/products/collateral/networking/sdwan-routers/8000-secure-routers/8100-series-secure-routers-ds.html" target="_blank"&gt;https://www.cisco.com/site/us/en/products/collateral/networking/sdwan-routers/8000-secure-routers/8100-series-secure-routers-ds.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Of course, there are also more powerful models with the 8200/8300 Series &lt;STRONG&gt;Secure&lt;/STRONG&gt; routers. The first link above leads to the data sheets for each series. Be careful not to mix them up with the old 8200/8300 Series routers (that's why I put the 'Secure' in bold).&lt;/P&gt;
&lt;P&gt;...and a final note.&lt;BR /&gt;These brand-new routers will be shipped with the same algorithms supported as of now. The hardware does support PQC security but the first software versions with quantum-resistant encryption are expected to be released some time next year. So patience is your best friend.&lt;/P&gt;
&lt;P&gt;HTH!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 01 Sep 2025 15:59:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ssh-weak-ciphers/m-p/5326216#M1122501</guid>
      <dc:creator>Jens Albrecht</dc:creator>
      <dc:date>2025-09-01T15:59:34Z</dc:date>
    </item>
    <item>
      <title>Re: SSH Weak Ciphers</title>
      <link>https://community.cisco.com/t5/network-security/ssh-weak-ciphers/m-p/5327788#M1122616</link>
      <description>&lt;P&gt;I replaced 4221 with 1121X router in support, and the IOS has been upgraded to the latest.&lt;BR /&gt;&lt;BR /&gt;i have no problems with&amp;nbsp;&lt;SPAN&gt;HMAC-SHA2-512-ETM, but it will not solve the scanner issue.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 06 Sep 2025 12:44:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ssh-weak-ciphers/m-p/5327788#M1122616</guid>
      <dc:creator>NMS2</dc:creator>
      <dc:date>2025-09-06T12:44:45Z</dc:date>
    </item>
  </channel>
</rss>

