<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Is TLSv2 applicable for SSH in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/disable-ssh-cbc-mode-cipher-encryption-and-disable-md5-and-96/m-p/2749310#M192909</link>
    <description>&lt;P&gt;Is TLSv2 applicable for SSH also? confirm.&lt;/P&gt;</description>
    <pubDate>Fri, 14 Aug 2015 03:32:11 GMT</pubDate>
    <dc:creator>balamuruganmanavalan</dc:creator>
    <dc:date>2015-08-14T03:32:11Z</dc:date>
    <item>
      <title>Disable SSH CBC mode cipher encryption and disable MD5 and 96-bit MAC algorithms in SSH on Cisco ASA</title>
      <link>https://community.cisco.com/t5/network-security/disable-ssh-cbc-mode-cipher-encryption-and-disable-md5-and-96/m-p/2749306#M192903</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Want to disable CBC mode cipher encryption, and enable CTR or GCM cipher mode encryption and disable MD5 and 96-bit MAC algorithms&lt;/P&gt;&lt;P&gt;ASA version : 9.1.5(21)&lt;/P&gt;&lt;P&gt;Any idea.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Bala&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 06:24:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/disable-ssh-cbc-mode-cipher-encryption-and-disable-md5-and-96/m-p/2749306#M192903</guid>
      <dc:creator>balamuruganmanavalan</dc:creator>
      <dc:date>2019-03-12T06:24:58Z</dc:date>
    </item>
    <item>
      <title>You can't, the options are</title>
      <link>https://community.cisco.com/t5/network-security/disable-ssh-cbc-mode-cipher-encryption-and-disable-md5-and-96/m-p/2749307#M192904</link>
      <description>&lt;P&gt;You can't, the options are quite limited. &lt;A href="https://supportforums.cisco.com/document/12338141/guide-better-ssh-security"&gt;But you can configure your SSH-clients not to negotiate weak ciphers&lt;/A&gt;.&lt;/P&gt;</description>
      <pubDate>Wed, 12 Aug 2015 12:34:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/disable-ssh-cbc-mode-cipher-encryption-and-disable-md5-and-96/m-p/2749307#M192904</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2015-08-12T12:34:35Z</dc:date>
    </item>
    <item>
      <title>Is any doc or cisco release</title>
      <link>https://community.cisco.com/t5/network-security/disable-ssh-cbc-mode-cipher-encryption-and-disable-md5-and-96/m-p/2749308#M192905</link>
      <description>&lt;P&gt;Is any doc or cisco&amp;nbsp;release notes stating that it is not possible?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Options are quite limited means?&lt;/P&gt;</description>
      <pubDate>Thu, 13 Aug 2015 06:03:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/disable-ssh-cbc-mode-cipher-encryption-and-disable-md5-and-96/m-p/2749308#M192905</guid>
      <dc:creator>balamuruganmanavalan</dc:creator>
      <dc:date>2015-08-13T06:03:51Z</dc:date>
    </item>
    <item>
      <title>If you want to use TLSv2</title>
      <link>https://community.cisco.com/t5/network-security/disable-ssh-cbc-mode-cipher-encryption-and-disable-md5-and-96/m-p/2749309#M192906</link>
      <description>&lt;P&gt;If you want to use TLSv2 ciphersuites you are going to have to upgrade to 9.3 or higher; they aren't supported on earlier versions.&lt;/P&gt;&lt;P&gt;-- Jim Leinweber, WI State Lab of Hygiene&lt;/P&gt;</description>
      <pubDate>Thu, 13 Aug 2015 19:12:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/disable-ssh-cbc-mode-cipher-encryption-and-disable-md5-and-96/m-p/2749309#M192906</guid>
      <dc:creator>James Leinweber</dc:creator>
      <dc:date>2015-08-13T19:12:52Z</dc:date>
    </item>
    <item>
      <title>Is TLSv2 applicable for SSH</title>
      <link>https://community.cisco.com/t5/network-security/disable-ssh-cbc-mode-cipher-encryption-and-disable-md5-and-96/m-p/2749310#M192909</link>
      <description>&lt;P&gt;Is TLSv2 applicable for SSH also? confirm.&lt;/P&gt;</description>
      <pubDate>Fri, 14 Aug 2015 03:32:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/disable-ssh-cbc-mode-cipher-encryption-and-disable-md5-and-96/m-p/2749310#M192909</guid>
      <dc:creator>balamuruganmanavalan</dc:creator>
      <dc:date>2015-08-14T03:32:11Z</dc:date>
    </item>
    <item>
      <title>No, TLS 1.2 in ASA versions 9</title>
      <link>https://community.cisco.com/t5/network-security/disable-ssh-cbc-mode-cipher-encryption-and-disable-md5-and-96/m-p/2749311#M192910</link>
      <description>&lt;P&gt;No, TLS 1.2 in ASA versions 9.3 and higher can be used with the actual AnyConnect client. But it's unrelated to SSH.&lt;/P&gt;</description>
      <pubDate>Fri, 14 Aug 2015 07:01:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/disable-ssh-cbc-mode-cipher-encryption-and-disable-md5-and-96/m-p/2749311#M192910</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2015-08-14T07:01:06Z</dc:date>
    </item>
    <item>
      <title>To my knowledge it's not</title>
      <link>https://community.cisco.com/t5/network-security/disable-ssh-cbc-mode-cipher-encryption-and-disable-md5-and-96/m-p/2749312#M192911</link>
      <description>&lt;P&gt;To my knowledge it's not documented that it's not possible ... Only the limited possibilities are documented, and that's mainly that you can restrict SSH to version 2 and configure the DH to group14.&lt;/P&gt;</description>
      <pubDate>Fri, 14 Aug 2015 07:03:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/disable-ssh-cbc-mode-cipher-encryption-and-disable-md5-and-96/m-p/2749312#M192911</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2015-08-14T07:03:36Z</dc:date>
    </item>
    <item>
      <title>Correct.Is there any cisco</title>
      <link>https://community.cisco.com/t5/network-security/disable-ssh-cbc-mode-cipher-encryption-and-disable-md5-and-96/m-p/2749313#M192912</link>
      <description>&lt;P&gt;Correct.&lt;/P&gt;&lt;P&gt;Is there any cisco doc or release note showing that no workaround in Cisco ASA for SSH vulnerability.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If limited possibilities are documented, at least share that link.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 14 Aug 2015 07:05:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/disable-ssh-cbc-mode-cipher-encryption-and-disable-md5-and-96/m-p/2749313#M192912</guid>
      <dc:creator>balamuruganmanavalan</dc:creator>
      <dc:date>2015-08-14T07:05:30Z</dc:date>
    </item>
    <item>
      <title>All what you can do is</title>
      <link>https://community.cisco.com/t5/network-security/disable-ssh-cbc-mode-cipher-encryption-and-disable-md5-and-96/m-p/2749314#M192913</link>
      <description>&lt;P&gt;All what you can do is documented in the config-guide.&lt;/P&gt;</description>
      <pubDate>Fri, 14 Aug 2015 07:08:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/disable-ssh-cbc-mode-cipher-encryption-and-disable-md5-and-96/m-p/2749314#M192913</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2015-08-14T07:08:19Z</dc:date>
    </item>
    <item>
      <title>you are referring which</title>
      <link>https://community.cisco.com/t5/network-security/disable-ssh-cbc-mode-cipher-encryption-and-disable-md5-and-96/m-p/2749315#M192914</link>
      <description>&lt;P&gt;you are referring which config-guide. can you share the link?&lt;/P&gt;</description>
      <pubDate>Fri, 14 Aug 2015 10:30:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/disable-ssh-cbc-mode-cipher-encryption-and-disable-md5-and-96/m-p/2749315#M192914</guid>
      <dc:creator>balamuruganmanavalan</dc:creator>
      <dc:date>2015-08-14T10:30:57Z</dc:date>
    </item>
    <item>
      <title>http://www.cisco.com/c/en/us</title>
      <link>https://community.cisco.com/t5/network-security/disable-ssh-cbc-mode-cipher-encryption-and-disable-md5-and-96/m-p/2749316#M192915</link>
      <description>&lt;P&gt;&lt;A href="http://www.cisco.com/c/en/us/td/docs/security/asa/asa91/configuration/general/asa_91_general_config/admin_management.html"&gt;http://www.cisco.com/c/en/us/td/docs/security/asa/asa91/configuration/general/asa_91_general_config/admin_management.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/c/en/us/td/docs/security/asa/asa-command-reference/S/cmdref3/s16.html"&gt;http://www.cisco.com/c/en/us/td/docs/security/asa/asa-command-reference/S/cmdref3/s16.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 14 Aug 2015 10:43:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/disable-ssh-cbc-mode-cipher-encryption-and-disable-md5-and-96/m-p/2749316#M192915</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2015-08-14T10:43:29Z</dc:date>
    </item>
    <item>
      <title>If we enable SSH</title>
      <link>https://community.cisco.com/t5/network-security/disable-ssh-cbc-mode-cipher-encryption-and-disable-md5-and-96/m-p/2749317#M192916</link>
      <description>&lt;P&gt;If we enable SSH authentication, can we mitigate that vulnerability?&lt;/P&gt;</description>
      <pubDate>Fri, 14 Aug 2015 12:28:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/disable-ssh-cbc-mode-cipher-encryption-and-disable-md5-and-96/m-p/2749317#M192916</guid>
      <dc:creator>balamuruganmanavalan</dc:creator>
      <dc:date>2015-08-14T12:28:18Z</dc:date>
    </item>
    <item>
      <title>SSH always works with</title>
      <link>https://community.cisco.com/t5/network-security/disable-ssh-cbc-mode-cipher-encryption-and-disable-md5-and-96/m-p/2749318#M192917</link>
      <description>&lt;P&gt;SSH always works with authentication. That's not related to the used ciphers.&lt;/P&gt;</description>
      <pubDate>Fri, 14 Aug 2015 12:51:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/disable-ssh-cbc-mode-cipher-encryption-and-disable-md5-and-96/m-p/2749318#M192917</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2015-08-14T12:51:06Z</dc:date>
    </item>
  </channel>
</rss>

