09-25-2017 01:41 AM - edited 03-08-2019 07:24 PM
We noticed that the SSH server of Cisco ESA is configured to use the weak encryption algorithms (arcfour, arcfour128 & arcfour256, cbc) and mac algorithms (hmac-sha1 and hmac-md5).
My question is:
How to disable SHA1 key algorithms?
How to disable CBC mode ciphers and use CTR mode ciphers?
How to disable 96-bit HMAC Algorithms?
Thanks.
Solved! Go to Solution.
09-25-2017 02:05 AM
You can modify the ciphers in use from the command line of the appliance using command "sshconfig".
- Libin V
09-27-2017 05:45 AM
09-25-2017 02:05 AM
You can modify the ciphers in use from the command line of the appliance using command "sshconfig".
- Libin V
09-27-2017 05:45 AM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide