cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1749
Views
0
Helpful
6
Replies

Key exchange algorithms on 6504E

andromeda
Level 1
Level 1

Could someone here please help me answer this question: have a 6504E running on 15.5(1)SY5 (latest) and need to know if its KEX algorithms can be updated somehow to a more modern set, currently only supporting diffie-hellman-group-exchange-sha1. 

 

Thanks!

6 Replies 6

balaji.bandi
Hall of Fame
Hall of Fame

Thanks, appreciate it. However that doesn't cover KEX on the cisco switch...

You could try the following command (replace <size> with the value you need or use ? to see what is available):

ip ssh dh min size <size>

--
Please remember to select a correct answer and rate helpful posts

Thank you, but that also doesn't address my concern. The KEX available still show dh with sha-1 only.

Came across this document.  Hopefully it will point you in the right direction.

https://community.cisco.com/t5/security-documents/guide-to-better-ssh-security/ta-p/3133344

--
Please remember to select a correct answer and rate helpful posts

Thanks, that's the same doc shared on the 1st reply. Unfortunately it does not address my question.

Review Cisco Networking for a $25 gift card