LinuxQuestions.org
Review your favorite Linux distribution.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 01-07-2015, 06:52 PM   #1
lleb
Senior Member
 
Registered: Dec 2005
Location: Florida
Distribution: CentOS/Fedora/Pop!_OS
Posts: 2,983

Rep: Reputation: 551Reputation: 551Reputation: 551Reputation: 551Reputation: 551Reputation: 551
question about some of the options in this link


https://stribika.github.io/2015/01/0...ure-shell.html

This is a nice little write up on how to harden your ssh connections in light of the Snowden documents about the NSA.

in the first section:
Code:
KexAlgorithms curve25519-sha256@libssh.org,diffie-hellman-group-exchange-sha256
When I attempted to add this to my config file both my MAC and my CentOS v7 system tossed a rather nasty fit. the KexAlgorithms.... is not found and or unknown.

Lower in the Symmetric ciphers, they talk about the chacha20-poly1305, but when attempting to implement this in addition to the aes256 ciphers I currently have in my config it again tossed up nasty little notices stating not found, etc...

tried both
Code:
chacha20-poly1305@openssh.com 
chacha20-poly1305
so both with and without the @openssh.com no luv.

in the Message authentication codes (MACs) how do I implement this on my systems?

tried just the first portion of their snippet:

Code:
MACs hmac-sha2-512-etm@openssh.com
and my system told me
Code:
no matching mac found: client hmac-sha2-512-etm@openssh.com server hmac-md5,hmssh.com,hmac-ripemd160,hmac-ripemd160@openssh.com,hmac-sha1-96,hmac-md5-96
Seems like a handy thing to add to the system for a bit more secure traffic between my home servers, web server, e-mail server, and my laptops when on the road.

thanks in advance.
 
Old 01-07-2015, 07:02 PM   #2
Miati
Member
 
Registered: Dec 2014
Distribution: Linux Mint 17.*
Posts: 326

Rep: Reputation: 106Reputation: 106
What version of ssh are you running?
If it's old, try updating it.

Have you looked through the man pages of sshd_config?

Mine didn't throw any issues & I have OpenSSH_6.6.1

Check this link about the osx not working

Last edited by Miati; 01-07-2015 at 07:18 PM.
 
Old 01-08-2015, 06:54 AM   #3
lleb
Senior Member
 
Registered: Dec 2005
Location: Florida
Distribution: CentOS/Fedora/Pop!_OS
Posts: 2,983

Original Poster
Rep: Reputation: 551Reputation: 551Reputation: 551Reputation: 551Reputation: 551Reputation: 551
Code:
$ ssh -V
OpenSSH_6.4p1, OpenSSL 1.0.1e-fips 11 Feb 2013
This is the most current for RHELv7 as Im running CentOS v7. Thanks for the link, yeah OSx has some strangeness at times with many of the "FOSS" protocols and software it runs.

attempting to update the OSx vs of ssh and see what flies from there.

will report back.
 
Old 01-08-2015, 07:49 AM   #4
lleb
Senior Member
 
Registered: Dec 2005
Location: Florida
Distribution: CentOS/Fedora/Pop!_OS
Posts: 2,983

Original Poster
Rep: Reputation: 551Reputation: 551Reputation: 551Reputation: 551Reputation: 551Reputation: 551
hmm turns out my OSx is just way to old to update and do anything about. still running 10.6.x old hardware. first gen Intel iMAC.

also there seems to be several bug reports out there from RH about their ssh and the above issues. oh well. maybe someday .
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
gcc compiles auth-options.c ,with '-c' option, but it will not link the object file. 0x61 Linux - General 3 01-22-2014 04:23 PM
basic html question - download link to files on my webpage question Davno Linux - Server 5 12-25-2009 07:24 AM
Small question about /etc/rc.local - Symbolic link question Arodef Linux - General 4 05-13-2006 02:29 AM
C/C++ Compile/Link options in Makefiles George_gk Programming 2 01-29-2005 07:53 PM
Kernel 2.6.2 options question - LOCKED options ? tvojvodi Linux - General 0 02-17-2004 04:23 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 01:00 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration