perfsonar-user - [perfsonar-user] Disable weak crypto ciphers
Subject: perfSONAR User Q&A and Other Discussion
List archive
- From: "Nickless, Bill" <>
- To: "''" <>
- Cc: "O'Leary, Shaun" <>, "Lenaeus, Joseph D" <>, "Bemis, Garrett A" <>, "Sailer, Timothy" <>, "Kissire, Tracy L" <>, "Page, Jon T" <>
- Subject: [perfsonar-user] Disable weak crypto ciphers
- Date: Wed, 27 Apr 2016 20:53:50 +0000
- Accept-language: en-US
Good afternoon,
The people responsible for PNNL network hygiene routinely scan our perfSONAR
hosts. People from big DOE also scan our perfSONAR hosts. The managers at
PNNL want a squeaky clean report from both the big DOE and PNNL scanners. To
get that that they want us to disable certain SSH ciphers.
Would you please update the perfSONAR configuration scripts to append these
three lines to /etc/ssh/sshd_config so that our local fix doesn't get
overwritten in the future? I see you're already forcing SSH Protocol 2,
which is a great start.
# Disable weak SSH crypto algorithms
Ciphers aes128-ctr,aes192-ctr,aes256-ctr
MACs hmac-sha1,hmac-sha1-96,hmac-sha2-256,hmac-sha2-512
Thank you and best regards,
Bill Nickless /
/ +1 509 713 2455
- [perfsonar-user] Disable weak crypto ciphers, Nickless, Bill, 04/27/2016
- <Possible follow-up(s)>
- Re: [perfsonar-user] Disable weak crypto ciphers, Mark Feit, 04/27/2016
Archive powered by MHonArc 2.6.16.