Got it

SSH weak MAC algorithms enabled

Created: Apr 14, 2020 12:17:08Latest reply: Apr 14, 2020 12:36:10 276 2 0 0 0
  Rewarded HiCoins: 0 (problem resolved)

Hi,

Our customer get a report “SSH weak MAC algorithms enabled” after the security scanning. I checked the scanning result and found the enabled MAC algorithms including hmac-sha2-256, hmac-sha2-256-96 and hmac-sha1-96.

Kindly help to figure out which algorithm(s) should I remove to terminate the weak algorithms enabled warning?

BTW, the switch is CE5855, and version is V200R005C00.

Thanks.


  • x
  • convention:

Featured Answers

Best answer

Recommended answer

chenhui
Admin Created Apr 14, 2020 12:36:10

Hi @user_3445655,
From the documentation, the weak algorithms of the algorithms your listed are hmac-sha2-256-96 and hmac-sha1-96.
Kindly disable these two algorithms to terminate the warnings.
You can refer to the example below:
<HUAWEI> system-view
[~HUAWEI] ssh server hmac sha2_256

For more deatils, you can refer to https://support.huawei.com/hedex/hdx.do?docid=EDOC1100020548&id=ssh_server_hmac&lang=en
View more
  • x
  • convention:

All Answers
chenhui
chenhui Admin Created Apr 14, 2020 12:19:37

Hi,
Kindly wait a second, we are processing on you problem.
View more
  • x
  • convention:

chenhui
chenhui Admin Created Apr 14, 2020 12:36:10

Hi @user_3445655,
From the documentation, the weak algorithms of the algorithms your listed are hmac-sha2-256-96 and hmac-sha1-96.
Kindly disable these two algorithms to terminate the warnings.
You can refer to the example below:
<HUAWEI> system-view
[~HUAWEI] ssh server hmac sha2_256

For more deatils, you can refer to https://support.huawei.com/hedex/hdx.do?docid=EDOC1100020548&id=ssh_server_hmac&lang=en
View more
  • x
  • convention:

Comment

You need to log in to comment to the post Login | Register
Comment

Notice: To protect the legitimate rights and interests of you, the community, and third parties, do not release content that may bring legal risks to all parties, including but are not limited to the following:
  • Politically sensitive content
  • Content concerning pornography, gambling, and drug abuse
  • Content that may disclose or infringe upon others ' commercial secrets, intellectual properties, including trade marks, copyrights, and patents, and personal privacy
Do not share your account and password with others. All operations performed using your account will be regarded as your own actions and all consequences arising therefrom will be borne by you. For details, see " Privacy."

My Followers

Login and enjoy all the member benefits

Login

Block
Are you sure to block this user?
Users on your blacklist cannot comment on your post,cannot mention you, cannot send you private messages.
Reminder
Please bind your phone number to obtain invitation bonus.