- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
08-06-2023 05:47 AM
Hello Cisco Community,
I have a customer that integrated a new version of SFTP Server which uses an SSH Cipher that the CUCM by default do not support.
I found that i can manually add new ciphers to CUCM via OS Administration > Security > Cipher Management and add the new cipher in the designated location.
What would be the impact on adding probably a single cipher key to either locations say "SSH Cipher" or "SSH Key Exchange"?
Solved! Go to Solution.
- Labels:
-
CUCM
-
Unified Communications
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
08-06-2023 06:49 PM
Hope this Helps.
-
SSH Ciphers—The ciphers that are assigned in this field are applicable to SSH connections on Unified Communications Manager and IM and Presence Service.
-
SSH Key Exchange—The Key Exchange algorithms that are assigned in this field are applicable to the SSH interface on Unified Communications Manager and IM and Presence Service.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
08-06-2023 11:50 PM
1) yes
2) depends which you ciphers you want to have enabled.
If you want the default + new ones, then you would paste all of those in the field and save it.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
08-06-2023 06:49 PM
Hope this Helps.
-
SSH Ciphers—The ciphers that are assigned in this field are applicable to SSH connections on Unified Communications Manager and IM and Presence Service.
-
SSH Key Exchange—The Key Exchange algorithms that are assigned in this field are applicable to the SSH interface on Unified Communications Manager and IM and Presence Service.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
08-06-2023 11:24 PM
I've read the Security guide before but it does say "When you configure ciphers on the Cipher Management page, the following ciphers are essentially disabled."
So i wanted to check if someone knew what would be the impact on the cluster if i were to add a SSH Cipher to the list, it would be the only one on the list because by default they are all empty
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
08-06-2023 11:35 PM
It's mentioned in the guide:
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
08-06-2023 11:46 PM
If i changed the default SSH Cipher it would only impact the SSH Cipher settings an no other right ?
and if i i change the SSH Cipher do i just include the default Ciphers base on the Guide + the new one that i need for the SFTP Server?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
08-06-2023 11:50 PM
1) yes
2) depends which you ciphers you want to have enabled.
If you want the default + new ones, then you would paste all of those in the field and save it.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
08-07-2023 12:07 AM
@Yarin Ezra wrote:
If i changed the default SSH Cipher it would only impact the SSH Cipher settings an no other right ?
and if i i change the SSH Cipher do i just include the default Ciphers base on the Guide + the new one that i need for the SFTP Server?
Thats True.
Add additional Ciphers to the list.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
08-07-2023 01:26 AM
how could i know what are the default ciphers for cucm version 11.5, are they the same values as the 12.5 like the guide above?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
08-07-2023 01:47 AM
Check the information of the corresponding enterprise parameters:
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
08-07-2023 01:52 AM
Awesome thank you, i noticed there were no parameter for SSH Cipher or Key Exchange, is there a way to find those as well? cant find anything about it anywhere
