08-06-2023 05:47 AM
Hello Cisco Community,
I have a customer that integrated a new version of SFTP Server which uses an SSH Cipher that the CUCM by default do not support.
I found that i can manually add new ciphers to CUCM via OS Administration > Security > Cipher Management and add the new cipher in the designated location.
What would be the impact on adding probably a single cipher key to either locations say "SSH Cipher" or "SSH Key Exchange"?
Solved! Go to Solution.
08-06-2023 06:49 PM
Hope this Helps.
SSH Ciphers—The ciphers that are assigned in this field are applicable to SSH connections on Unified Communications Manager and IM and Presence Service.
SSH Key Exchange—The Key Exchange algorithms that are assigned in this field are applicable to the SSH interface on Unified Communications Manager and IM and Presence Service.
08-06-2023 11:50 PM
1) yes
2) depends which you ciphers you want to have enabled.
If you want the default + new ones, then you would paste all of those in the field and save it.
08-06-2023 06:49 PM
Hope this Helps.
SSH Ciphers—The ciphers that are assigned in this field are applicable to SSH connections on Unified Communications Manager and IM and Presence Service.
SSH Key Exchange—The Key Exchange algorithms that are assigned in this field are applicable to the SSH interface on Unified Communications Manager and IM and Presence Service.
08-06-2023 11:24 PM
I've read the Security guide before but it does say "When you configure ciphers on the Cipher Management page, the following ciphers are essentially disabled."
So i wanted to check if someone knew what would be the impact on the cluster if i were to add a SSH Cipher to the list, it would be the only one on the list because by default they are all empty
08-06-2023 11:35 PM
It's mentioned in the guide:
08-06-2023 11:46 PM
If i changed the default SSH Cipher it would only impact the SSH Cipher settings an no other right ?
and if i i change the SSH Cipher do i just include the default Ciphers base on the Guide + the new one that i need for the SFTP Server?
08-06-2023 11:50 PM
1) yes
2) depends which you ciphers you want to have enabled.
If you want the default + new ones, then you would paste all of those in the field and save it.
08-07-2023 12:07 AM
@Yarin Ezra wrote:
If i changed the default SSH Cipher it would only impact the SSH Cipher settings an no other right ?
and if i i change the SSH Cipher do i just include the default Ciphers base on the Guide + the new one that i need for the SFTP Server?
Thats True.
Add additional Ciphers to the list.
08-07-2023 01:26 AM
how could i know what are the default ciphers for cucm version 11.5, are they the same values as the 12.5 like the guide above?
08-07-2023 01:47 AM
Check the information of the corresponding enterprise parameters:
08-07-2023 01:52 AM
Awesome thank you, i noticed there were no parameter for SSH Cipher or Key Exchange, is there a way to find those as well? cant find anything about it anywhere
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide