cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Announcements

593
Views
0
Helpful
6
Replies
Highlighted
Beginner

Key exchange algorithms on 6504E

Could someone here please help me answer this question: have a 6504E running on 15.5(1)SY5 (latest) and need to know if its KEX algorithms can be updated somehow to a more modern set, currently only supporting diffie-hellman-group-exchange-sha1. 

 

Thanks!

6 REPLIES 6
Highlighted
VIP Mentor

here is the latest information :

 

https://community.cisco.com/t5/security-documents/guide-to-better-ssh-security/ta-p/3133344

BB
*** Rate All Helpful Responses ***
Highlighted

Thanks, appreciate it. However that doesn't cover KEX on the cisco switch...

Highlighted

You could try the following command (replace <size> with the value you need or use ? to see what is available):

ip ssh dh min size <size>

--
Please remember to select a correct answer and rate helpful posts
Highlighted

Thank you, but that also doesn't address my concern. The KEX available still show dh with sha-1 only.

Highlighted

Came across this document.  Hopefully it will point you in the right direction.

https://community.cisco.com/t5/security-documents/guide-to-better-ssh-security/ta-p/3133344

--
Please remember to select a correct answer and rate helpful posts
Highlighted

Thanks, that's the same doc shared on the 1st reply. Unfortunately it does not address my question.

Content for Community-Ad