Forum Discussion

Mate_132781's avatar
Mate_132781
Icon for Cirrostratus rankCirrostratus
Sep 08, 2015

BIG-IP 11.6 - Disable MD5 and 96-bit MAC algorithms and CBC mode for SSH

Hi,

 

our customer has BIG-IP 2000s with 11.6 HF4 TMOS, they had security audit which ends with 2 vulnerabilities and action points:

 

The SSH server is configured to allow either MD5 or 96-bit MAC algorithms, both of which are considered weak.

 

  • disable MD5 and 96bit MAC algorithms

The SSH server is configured to support Cipher Block Chaining (CBC) encryption. This may allow an attacker to recover the plaintext message from the ciphertext.

 

  • disable CBC mode cipher encryption, and enable CTR or GCM cipher mode encryption

Can you pls help me how to disable MD5 and 96-bit algorithms and CBC mode cipher encryption (and enable CTR or GCM cipher mode encryption) for SSH?