0
Votes

Update the list of supported suites for SSH

  This repeated request has been merged into the main thread Backup to SFTP: software controlled uses deprecated key algorithms. Please vote on the main thread.

 
0
Votes

Update the list of supported suites for SSH

  This repeated request has been merged into the main thread Backup to SFTP: software controlled uses deprecated key algorithms. Please vote on the main thread.
Update the list of supported suites for SSH
Update the list of supported suites for SSH
2 weeks ago - last edited 2 weeks ago
Model: OC200  
Hardware Version: V1
Firmware Version: 5.15.24

Hello,

 

Recently I wanted to set up the backup feature in the controller, but I got errors instead.

My server's auth log stated:

 

Aug 17 12:51:45 <my_server> sshd[3859440]: error: Received disconnect from <controller_ip> port 55986:3: com.jcraft.jsch.JSchException: java.lang.ClassNotFoundException: com.jcraft.jsch.DHGEX256 [preauth]

 

Sure, I could get around that, but this isn't addressing the issue - controller relies on suites (here: KEX) that are now considered to be legacy.

This is quite weird because I've used software controller before moving to OC200 and though I have a basic hardening (CIS v2), it worked like a charm. It's like software-based and hardware-based controllers are deployed from entirely different branches.

 

Anyway, since this seems to be a matter of updating a single file in the release to make it support modern suites, could you please include that in the future release?

 

#1
Options
8 Reply
Re:Update the list of supported suites for SSH
2 weeks ago

Hi  @meowing_parrot 

 

Thanks for posting here.

To confirm,

1. is the mentioned backup feature referring to the WAN link backup?

 

2. Do you mean it worked well on software controllers?

#2
Options
Re:Update the list of supported suites for SSH
2 weeks ago

Hello  @Vincent-TP 

 

No, not at all, this has nothing to do with link whatsoever. I'm referring to the regular backup (and backup schedule), found under Settings -> Maintenance.

#3
Options
Re:Update the list of supported suites for SSH
2 weeks ago - last edited 2 weeks ago

Hi  @meowing_parrot 

 

Thanks for the clarification.

Before confirming with others if this is really lacked, please let us know:

 

Does this work on software controllers?

 

Recently I wanted to set up the backup feature in the controller, but I got errors instead.

>>>One more question, what error will you see? can you share with a screenshot?

 

#4
Options
Re:Update the list of supported suites for SSH
2 weeks ago

 

I am not able to send a regular post, I'm getting an absurd error, so I had to resort to posting an image instead of actual text.
Could someone explain what the heck is going on here? What external links?

 

#5
Options
Re:Update the list of supported suites for SSH
2 weeks ago

Hey @Vincent-TP - you probably didn't get a notification as the previous post contents are mostly images, so I'm just dropping a reply to let you know I've answered.

#6
Options
Re:Update the list of supported suites for SSH
2 weeks ago

Hi  @meowing_parrot 

 

Thanks for the remind.

 

You may have a look at the following post,  cast your vote and add your comments. I will feedback to our team together. Thanks.

 

Backup to SFTP: software controlled uses deprecated key algorithms

 

#7
Options
Re:Update the list of supported suites for SSH
2 weeks ago

Hi  @Vincent-TP 

 

Thank you, done. Do I need to do anything apart from clicking the upvote button and providing comments there?

#8
Options
Re:Update the list of supported suites for SSH
2 weeks ago

Hi  @meowing_parrot 

 

Thanks for that. Nothing else needed yet. 

 

 

Side Note: I  merged this post with the other post to focus the discussion on this topic.

#9
Options