<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic SSH Weak Key Exchange Algorithms Enabled in ExtremeSwitching (EOS)</title>
    <link>https://community.extremenetworks.com/t5/extremeswitching-eos/ssh-weak-key-exchange-algorithms-enabled/m-p/57875#M1180</link>
    <description>Hi Team ,&lt;BR /&gt;&lt;BR /&gt;I am facing issue in Extreme switches for SSH Weak Key Exchange Algorithms Enabled . Can anybody help how to remove this thing .&lt;BR /&gt;&lt;SPAN style="background-color: #ffff00;"&gt;&lt;STRONG&gt;System Type: NWI-E450A&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;SPAN style="background-color: #ffff00;"&gt; Created by ExtremeXOS version 16.2.3.5&lt;/SPAN&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;BR /&gt;The remote SSH server is configured to allow key exchange algorithms which are considered weak.&lt;BR /&gt;&lt;BR /&gt;This is based on the IETF draft document Key Exchange (KEX) Method Updates and Recommendations for Secure Shell (SSH)&lt;BR /&gt;draft-ietf-curdle-ssh-kex-sha2-20. Section 4 lists guidance on key exchange algorithms that SHOULD NOT and MUST NOT be&lt;BR /&gt;enabled. This includes:&lt;BR /&gt;&lt;BR /&gt;diffie-hellman-group-exchange-sha1&lt;BR /&gt;&lt;BR /&gt;diffie-hellman-group1-sha1&lt;BR /&gt;&lt;BR /&gt;gss-gex-sha1-*&lt;BR /&gt;&lt;BR /&gt;gss-group1-sha1-*&lt;BR /&gt;&lt;BR /&gt;gss-group14-sha1-*&lt;BR /&gt;&lt;BR /&gt;rsa1024-sha1&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Note that this plugin only checks for the options of the SSH server, and it does not check for vulnerable software&lt;BR /&gt;versions.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;regards&amp;nbsp;&lt;BR /&gt;Parvinder SIngh</description>
    <pubDate>Tue, 15 Mar 2022 07:59:00 GMT</pubDate>
    <dc:creator>ParvinderS</dc:creator>
    <dc:date>2022-03-15T07:59:00Z</dc:date>
    <item>
      <title>SSH Weak Key Exchange Algorithms Enabled</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-eos/ssh-weak-key-exchange-algorithms-enabled/m-p/57875#M1180</link>
      <description>Hi Team ,&lt;BR /&gt;&lt;BR /&gt;I am facing issue in Extreme switches for SSH Weak Key Exchange Algorithms Enabled . Can anybody help how to remove this thing .&lt;BR /&gt;&lt;SPAN style="background-color: #ffff00;"&gt;&lt;STRONG&gt;System Type: NWI-E450A&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;SPAN style="background-color: #ffff00;"&gt; Created by ExtremeXOS version 16.2.3.5&lt;/SPAN&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;BR /&gt;The remote SSH server is configured to allow key exchange algorithms which are considered weak.&lt;BR /&gt;&lt;BR /&gt;This is based on the IETF draft document Key Exchange (KEX) Method Updates and Recommendations for Secure Shell (SSH)&lt;BR /&gt;draft-ietf-curdle-ssh-kex-sha2-20. Section 4 lists guidance on key exchange algorithms that SHOULD NOT and MUST NOT be&lt;BR /&gt;enabled. This includes:&lt;BR /&gt;&lt;BR /&gt;diffie-hellman-group-exchange-sha1&lt;BR /&gt;&lt;BR /&gt;diffie-hellman-group1-sha1&lt;BR /&gt;&lt;BR /&gt;gss-gex-sha1-*&lt;BR /&gt;&lt;BR /&gt;gss-group1-sha1-*&lt;BR /&gt;&lt;BR /&gt;gss-group14-sha1-*&lt;BR /&gt;&lt;BR /&gt;rsa1024-sha1&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Note that this plugin only checks for the options of the SSH server, and it does not check for vulnerable software&lt;BR /&gt;versions.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;regards&amp;nbsp;&lt;BR /&gt;Parvinder SIngh</description>
      <pubDate>Tue, 15 Mar 2022 07:59:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-eos/ssh-weak-key-exchange-algorithms-enabled/m-p/57875#M1180</guid>
      <dc:creator>ParvinderS</dc:creator>
      <dc:date>2022-03-15T07:59:00Z</dc:date>
    </item>
  </channel>
</rss>

