<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic RE: Unable to negotiate ssh2 key algorithm in ExtremeSwitching (EXOS/Switch Engine)</title>
    <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/unable-to-negotiate-ssh2-key-algorithm/m-p/38365#M8261</link>
    <description>Hi Ihuso,&lt;BR /&gt;
&lt;BR /&gt;
ExtremeXOS 16.1 and earlier versions generated DSA-2048 keys using ssh-keygen provided by a theSSH-Toolkit library. Starting with ExtremeXOS 21.1, ExtremeXOS generates more secure RSA-2048 keys.&lt;BR /&gt;
&lt;BR /&gt;
As you said, In  OpenSSH 7.0 disables ssh-DSS keys by default, they are using RSA  for negotiating and it will not support in EXOS 16.1 and earlier is that we are getting the following error message.&lt;BR /&gt;
&lt;BR /&gt;
Unable to negotiate with x.x.x.x port 22: no matching&lt;BR /&gt;
host key type found. Their offer: ssh-DSS&lt;BR /&gt;
&lt;BR /&gt;</description>
    <pubDate>Thu, 22 Dec 2016 20:05:00 GMT</pubDate>
    <dc:creator>Baskar</dc:creator>
    <dc:date>2016-12-22T20:05:00Z</dc:date>
    <item>
      <title>Unable to negotiate ssh2 key algorithm</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/unable-to-negotiate-ssh2-key-algorithm/m-p/38364#M8260</link>
      <description>We use Linux clients with ssh2 and they all have OpenSSH 7.0 or newer. When connecting to our EXOS switches we get this error:&lt;BR /&gt;
&lt;BR /&gt;
Unable to negotiate with x.x.x.x port 22: no matching&lt;BR /&gt;
host key type found. Their offer: ssh-dss&lt;BR /&gt;
&lt;BR /&gt;
The switches use XOS 16.1.x and I have also tested with 16.2. Same result!&lt;BR /&gt;
&lt;BR /&gt;
OpenSSH  7.0 and greater similarly disable the ssh-dss (DSA) public key  algorithm. It is week and not recommended. &lt;BR /&gt;
Because of this we need to disable ssh-dss on the switches but is it possible? I know that more ssh2 variables can be changed and configured in XOS 21.1 and when using 21.1 we don't get the error about ssh-dss. Great, but I have very few G2 switches so I have to stick with 16.x for a long time.&lt;BR /&gt;
&lt;BR /&gt;
Ssh2 Secure mode have also been tested but it didn't solve the problem with ssh-dss.&lt;BR /&gt;
&lt;BR /&gt;
Have anybody else any experience with this on XOS 16.2 or lower versions?&lt;BR /&gt;</description>
      <pubDate>Thu, 22 Dec 2016 18:13:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/unable-to-negotiate-ssh2-key-algorithm/m-p/38364#M8260</guid>
      <dc:creator>lhuso</dc:creator>
      <dc:date>2016-12-22T18:13:00Z</dc:date>
    </item>
    <item>
      <title>RE: Unable to negotiate ssh2 key algorithm</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/unable-to-negotiate-ssh2-key-algorithm/m-p/38365#M8261</link>
      <description>Hi Ihuso,&lt;BR /&gt;
&lt;BR /&gt;
ExtremeXOS 16.1 and earlier versions generated DSA-2048 keys using ssh-keygen provided by a theSSH-Toolkit library. Starting with ExtremeXOS 21.1, ExtremeXOS generates more secure RSA-2048 keys.&lt;BR /&gt;
&lt;BR /&gt;
As you said, In  OpenSSH 7.0 disables ssh-DSS keys by default, they are using RSA  for negotiating and it will not support in EXOS 16.1 and earlier is that we are getting the following error message.&lt;BR /&gt;
&lt;BR /&gt;
Unable to negotiate with x.x.x.x port 22: no matching&lt;BR /&gt;
host key type found. Their offer: ssh-DSS&lt;BR /&gt;
&lt;BR /&gt;</description>
      <pubDate>Thu, 22 Dec 2016 20:05:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/unable-to-negotiate-ssh2-key-algorithm/m-p/38365#M8261</guid>
      <dc:creator>Baskar</dc:creator>
      <dc:date>2016-12-22T20:05:00Z</dc:date>
    </item>
    <item>
      <title>RE: Unable to negotiate ssh2 key algorithm</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/unable-to-negotiate-ssh2-key-algorithm/m-p/38366#M8262</link>
      <description>Thanks for your reply. &lt;BR /&gt;
&lt;BR /&gt;
So the final question is: What about 16.2?</description>
      <pubDate>Thu, 22 Dec 2016 20:56:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/unable-to-negotiate-ssh2-key-algorithm/m-p/38366#M8262</guid>
      <dc:creator>lhuso</dc:creator>
      <dc:date>2016-12-22T20:56:00Z</dc:date>
    </item>
    <item>
      <title>RE: Unable to negotiate ssh2 key algorithm</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/unable-to-negotiate-ssh2-key-algorithm/m-p/38367#M8263</link>
      <description>As I said ExtremeXOS 16.1 and earlier versions using DSA, the later versions like 16.2 and 21.1 ExtremXOS generates more secure using RSA keys.&lt;BR /&gt;
&lt;BR /&gt;
thank you &lt;BR /&gt;
&lt;BR /&gt;</description>
      <pubDate>Thu, 22 Dec 2016 21:12:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/unable-to-negotiate-ssh2-key-algorithm/m-p/38367#M8263</guid>
      <dc:creator>Baskar</dc:creator>
      <dc:date>2016-12-22T21:12:00Z</dc:date>
    </item>
    <item>
      <title>RE: Unable to negotiate ssh2 key algorithm</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/unable-to-negotiate-ssh2-key-algorithm/m-p/38368#M8264</link>
      <description>But we get the same error in 16.2 even if we use Secure mode!&lt;BR /&gt;
&lt;BR /&gt;</description>
      <pubDate>Thu, 22 Dec 2016 21:17:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/unable-to-negotiate-ssh2-key-algorithm/m-p/38368#M8264</guid>
      <dc:creator>lhuso</dc:creator>
      <dc:date>2016-12-22T21:17:00Z</dc:date>
    </item>
    <item>
      <title>RE: Unable to negotiate ssh2 key algorithm</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/unable-to-negotiate-ssh2-key-algorithm/m-p/38369#M8265</link>
      <description>I Belive configuring  ssh will help us to resolve the issue (configure ssh2 key), because 16.2 has backward compatibility to DSA.&lt;BR /&gt;
please let me know above one helped to resolve the issue.&lt;BR /&gt;
&lt;BR /&gt;</description>
      <pubDate>Fri, 23 Dec 2016 14:07:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/unable-to-negotiate-ssh2-key-algorithm/m-p/38369#M8265</guid>
      <dc:creator>Baskar</dc:creator>
      <dc:date>2016-12-23T14:07:00Z</dc:date>
    </item>
    <item>
      <title>RE: Unable to negotiate ssh2 key algorithm</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/unable-to-negotiate-ssh2-key-algorithm/m-p/38370#M8266</link>
      <description>Hello lhuso,&lt;BR /&gt;
&lt;BR /&gt;
Put next lines into your client's ssh config file "~/.ssh/config" &lt;BR /&gt;
&lt;BR /&gt;
Host &lt;I&gt; &lt;BR /&gt;
HostKeyAlgorithms +ssh-dss &lt;BR /&gt;
KexAlgorithms +diffie-hellman-group1-sha1 &lt;BR /&gt;
&lt;BR /&gt;
Best Regards,&lt;BR /&gt;
Nikolay&lt;/I&gt;</description>
      <pubDate>Fri, 23 Dec 2016 17:42:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/unable-to-negotiate-ssh2-key-algorithm/m-p/38370#M8266</guid>
      <dc:creator>Necheporenko__N</dc:creator>
      <dc:date>2016-12-23T17:42:00Z</dc:date>
    </item>
  </channel>
</rss>

