1752826 Members
4259 Online
108789 Solutions
New Discussion

kexalgorithms

 
pjbell
Occasional Visitor

kexalgorithms

i have a few servers running:OpenSSH_5.6p1+sftpfilecontrol-v1.3-hpn13v7, OpenSSL 0.9.8o 01 Jun 2010
HP-UX Secure Shell-A.05.60.001, HP-UX Secure Shell version

i need to remove the possibility for connections to these servers to offer or accept the kexlgorithm "diffie-hellman-group-exchange-sha1"

in Solaris & Linux i can accomplish this by upgrading OpenSSl  to:

OpenSSH_5.3p1, OpenSSL 1.0.1e-fips 11 Feb 2013 which allows one to specify acceptable Ciphers, MACs, and kexlgorithms in ssh_config and sshd_config.

is this same method available in HP-UX?

if yes, where can i obtain the requisit modules and a pointer to the instruction for the upgrade?

    -paul

 

 

1 REPLY 1
PSPrakash
HPE Pro

Re: kexalgorithms

Hello

Latest HPUX SecureShell versions available at below link
https://h20392.www2.hpe.com/portal/swdepot/displayProductInfo.do?productNumber=T1471AA 

and you may modify the "/opt/ssh/etc/sshd_config" file  in older version to achive it


I am an HPE employee

Accept or Kudo