Skip to Content.
Sympa Menu

perfsonar-user - [perfsonar-user] Disable weak crypto ciphers

Subject: perfSONAR User Q&A and Other Discussion

List archive

[perfsonar-user] Disable weak crypto ciphers


Chronological Thread 
  • From: "Nickless, Bill" <>
  • To: "''" <>
  • Cc: "O'Leary, Shaun" <>, "Lenaeus, Joseph D" <>, "Bemis, Garrett A" <>, "Sailer, Timothy" <>, "Kissire, Tracy L" <>, "Page, Jon T" <>
  • Subject: [perfsonar-user] Disable weak crypto ciphers
  • Date: Wed, 27 Apr 2016 20:53:50 +0000
  • Accept-language: en-US

Good afternoon,

The people responsible for PNNL network hygiene routinely scan our perfSONAR
hosts. People from big DOE also scan our perfSONAR hosts. The managers at
PNNL want a squeaky clean report from both the big DOE and PNNL scanners. To
get that that they want us to disable certain SSH ciphers.

Would you please update the perfSONAR configuration scripts to append these
three lines to /etc/ssh/sshd_config so that our local fix doesn't get
overwritten in the future? I see you're already forcing SSH Protocol 2,
which is a great start.

# Disable weak SSH crypto algorithms
Ciphers aes128-ctr,aes192-ctr,aes256-ctr
MACs hmac-sha1,hmac-sha1-96,hmac-sha2-256,hmac-sha2-512

Thank you and best regards,

Bill Nickless /

/ +1 509 713 2455



Archive powered by MHonArc 2.6.16.

Top of Page