- Community Home
- >
- Servers and Operating Systems
- >
- HPE ProLiant
- >
- Servers - General
- >
- HP DL380 G9 - SSH SHA-1 HMAC Algorithms Enabled...
Categories
Company
Local Language
Forums
Discussions
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Discussions
Discussions
Discussions
Forums
Discussions
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
- BladeSystem Infrastructure and Application Solutions
- Appliance Servers
- Alpha Servers
- BackOffice Products
- Internet Products
- HPE 9000 and HPE e3000 Servers
- Networking
- Netservers
- Secure OS Software for Linux
- Server Management (Insight Manager 7)
- Windows Server 2003
- Operating System - Tru64 Unix
- ProLiant Deployment and Provisioning
- Linux-Based Community / Regional
- Microsoft System Center Integration
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Community
Resources
Forums
Blogs
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
04-03-2023 09:59 AM - last edited on 04-05-2023 04:26 AM by support_s
04-03-2023 09:59 AM - last edited on 04-05-2023 04:26 AM by support_s
HP DL380 G9 - SSH SHA-1 HMAC Algorithms Enabled (Port 22) - Vulnerability on ILO (RAC)
Could you please let me know to resolve vulnerabiltiy on remote management console
Vulnerability Name: HP DL380 G9- SSH SHA-1 HMAC Algorithms Enabled (Port 22) on ILO 4
- Tags:
- Port
- Prolaint server
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
04-03-2023 11:00 AM
04-03-2023 11:00 AM
Query: HP DL380 G9 - SSH SHA-1 HMAC Algorithms Enabled (Port 22) - Vulnerability on ILO (RAC)
System recommended content:
1. HPE Integrated Lights Out 4 (iLO 4) - Troubleshooting Login and iLO Access Issues
2. HPE Integrated Lights-Out 4 (iLO 4) - How to Reset iLO Management Processor and iLO Password?
Please click on "Thumbs Up/Kudo" icon to give a "Kudo".
Thank you for being a HPE valuable community member.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
04-04-2023 11:23 PM
04-04-2023 11:23 PM
Re: HP DL380 G9 - SSH SHA-1 HMAC Algorithms Enabled (Port 22) - Vulnerability on ILO (R
The vulnerability you mentioned is related to the use of insecure cryptographic algorithms (SHA-1 and HMAC) on the SSH service (port 22) of the Integrated Lights-Out (iLO) management interface on an HP DL380 G9 server.
In order to address this vulnerability, you should disable the use of SHA-1 and HMAC algorithms on the SSH service of iLO 4. You can do this by following the steps below:
- Log in to the iLO web interface using an administrative account.
- Click on the "Administration" tab and select "Security".
- Under "Security", select "SSH" and click on "Advanced Settings".
- In the "Advanced Settings" section, look for the "MAC algorithms" option and uncheck the "hmac-sha1" checkbox.
- Next, look for the "Key exchange algorithms" option and uncheck the "diffie-hellman-group1-sha1" checkbox.
- Click on "Apply" to save the changes.
After completing these steps, the iLO SSH service will no longer allow the use of insecure SHA-1 and HMAC algorithms, which will mitigate the vulnerability you described. It is also recommended to keep your server firmware and iLO firmware up-to-date to ensure the latest security patches are installed.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
08-28-2024 07:34 AM - last edited on 09-16-2024 02:08 AM by support_s
08-28-2024 07:34 AM - last edited on 09-16-2024 02:08 AM by support_s
Re: HP DL380 G9 - SSH SHA-1 HMAC Algorithms Enabled (Port 22) - Vulnerability on ILO (R
How to apply same settings in iLO 5?
After checking all items in iLO5, there is no option for disabling SHA1 MAC algorithms
Thanx in advanced
- Tags:
- iLO_OA
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
08-30-2024 02:31 AM
08-30-2024 02:31 AM
Re: HP DL380 G9 - SSH SHA-1 HMAC Algorithms Enabled (Port 22) - Vulnerability on ILO (R
Hello @sakura87c,
Thank you for writing to us!
You might want to consider creating a new topic by utilizing the "New Discussion" button, as this will not only enhance visibility compared to the old topic but also boost your chances of receiving responses from experts.
Thanks,
Sunitha G
I'm an HPE employee.
HPE Support Center offers support for your HPE services and products when and how you need it. Get started with HPE Support Center today.
[Any personal opinions expressed are mine, and not official statements on behalf of Hewlett Packard Enterprise]
