04-25-2018 02:22 AM - edited 03-08-2019 07:36 PM
Hello,
I would like to know how to edit and configure the SSL Certificate and SSH Server on Cisco SMA.
SSH Server on Cisco SMA
1. how to disable CBC mode cipher encryption, and enable CTR or GCM cipher mode encryption.
2. how to disable MD5 and 96-bit MAC algorithms
3. how to remove the weak ciphers
Thanks.
04-25-2018 07:20 AM
You can review and modify the ciphers in use through the CLI using command sslconfig.
Refer to the article:
CLI command sshconfig to review and modify algorithms in use.
The SMA does have limited options compared to the ESA.
https://bst.cloudapps.cisco.com/bugsearch/bug/CSCzv84351/?rfs=iqvred
04-25-2018 07:46 PM
Hi Libin,
Thanks for your answer. The below articles are especially for SSL configuration on SMA.
But I need to edit and configuration of SSH on SMA. Please advise.
Thanks
04-30-2018 03:49 PM
You can use the CLI command sshconfig for the same.
However do note that modifying how ssh works can result in you loosing ssh access to the appliance depending on the ssh client in use.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide