<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ssl downgrade by default? in ExtremeSwitching (EXOS/Switch Engine)</title>
    <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/ssl-downgrade-by-default/m-p/38800#M8443</link>
    <description>Hey guys,&lt;BR /&gt;
&lt;BR /&gt;
When we ssh into a default install of exos, we're receving what appears to be a downgrade to a weak cipher/key exchange protocol:&lt;BR /&gt;
&lt;BR /&gt;
Unable to negotiate with 10.xx.xx.xx port 22: no matching key exchange method found. Their offer: diffie-hellman-group1-sha1&lt;BR /&gt;
&lt;BR /&gt;
Do you know when this might be fixed?</description>
    <pubDate>Tue, 21 Jun 2016 03:11:00 GMT</pubDate>
    <dc:creator>shampoo</dc:creator>
    <dc:date>2016-06-21T03:11:00Z</dc:date>
    <item>
      <title>ssl downgrade by default?</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/ssl-downgrade-by-default/m-p/38800#M8443</link>
      <description>Hey guys,&lt;BR /&gt;
&lt;BR /&gt;
When we ssh into a default install of exos, we're receving what appears to be a downgrade to a weak cipher/key exchange protocol:&lt;BR /&gt;
&lt;BR /&gt;
Unable to negotiate with 10.xx.xx.xx port 22: no matching key exchange method found. Their offer: diffie-hellman-group1-sha1&lt;BR /&gt;
&lt;BR /&gt;
Do you know when this might be fixed?</description>
      <pubDate>Tue, 21 Jun 2016 03:11:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/ssl-downgrade-by-default/m-p/38800#M8443</guid>
      <dc:creator>shampoo</dc:creator>
      <dc:date>2016-06-21T03:11:00Z</dc:date>
    </item>
    <item>
      <title>RE: ssl downgrade by default?</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/ssl-downgrade-by-default/m-p/38801#M8444</link>
      <description>What version of EXOS are you seeing this on? Also, what SSH client are you using?&lt;BR /&gt;
&lt;BR /&gt;
-Brandon</description>
      <pubDate>Tue, 21 Jun 2016 03:16:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/ssl-downgrade-by-default/m-p/38801#M8444</guid>
      <dc:creator>BrandonC</dc:creator>
      <dc:date>2016-06-21T03:16:00Z</dc:date>
    </item>
    <item>
      <title>RE: ssl downgrade by default?</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/ssl-downgrade-by-default/m-p/38802#M8445</link>
      <description>Hey Brandon,&lt;BR /&gt;
&lt;BR /&gt;
We're seeing this on v15.7.14 and are just using the terminal ssh client on Fedora 23&lt;BR /&gt;
&lt;BR /&gt;
Thanks</description>
      <pubDate>Tue, 21 Jun 2016 05:40:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/ssl-downgrade-by-default/m-p/38802#M8445</guid>
      <dc:creator>shampoo</dc:creator>
      <dc:date>2016-06-21T05:40:00Z</dc:date>
    </item>
    <item>
      <title>RE: ssl downgrade by default?</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/ssl-downgrade-by-default/m-p/38803#M8446</link>
      <description>Ahh yes.. This is what I do&lt;BR /&gt;
&lt;BR /&gt;
ssh -oHostKeyAlgorithms=+ssh-dss  -l USERNAME IPADDRESS&lt;BR /&gt;
&lt;BR /&gt;
Should be able to add this to your ~/.ssh/config&lt;BR /&gt;
&lt;BR /&gt;
HostkeyAlgorithms +ssh-dss&lt;BR /&gt;
&lt;BR /&gt;
That way you don't have to type in the -oHostKeyAlg...&lt;BR /&gt;
&lt;BR /&gt;</description>
      <pubDate>Tue, 21 Jun 2016 08:58:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/ssl-downgrade-by-default/m-p/38803#M8446</guid>
      <dc:creator>Jeremy_Gibbs</dc:creator>
      <dc:date>2016-06-21T08:58:00Z</dc:date>
    </item>
  </channel>
</rss>

