LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Server
User Name
Password
Linux - Server This forum is for the discussion of Linux Software used in a server related context.

Notices


Reply
  Search this Thread
Old 08-12-2022, 06:28 AM   #1
1s440
Member
 
Registered: Mar 2018
Posts: 266

Rep: Reputation: Disabled
ssh connectivity issues


Hi all,

when i tried to connect via ssh, then i get the below error
Code:
Unable to negotiate port 22: no matching cipher found. Their offer: 3des-cbc
If i pass ciphers to the ssh command then I get
Code:
Received disconnect port 22:2:  Client Disconnect
Can anyone suggests?
 
Old 08-12-2022, 06:33 AM   #2
suramya
Member
 
Registered: Jan 2022
Location: Earth
Distribution: Debian
Posts: 249

Rep: Reputation: 102Reputation: 102
The *-cbc protocols have a vulnerability in them and the recent versions of SSH reject them by default.
You can try the workaround as per https://unix.stackexchange.com/quest...-rejecting-cbc but I would suggest that you upgrade the SSH version of the server as soon as possible.

- Suramya
 
2 members found this post helpful.
Old 08-12-2022, 09:11 AM   #3
elgrandeperro
Member
 
Registered: Apr 2021
Posts: 415
Blog Entries: 2

Rep: Reputation: Disabled
On the server side, you can set the ciphers in /etc/ssh/ssshd_config:

Ciphers aes128-ctr,aes192-ctr,aes256-ctr,aes128-cbc,3des-cbc,aes192-cbc,aes256-cbc

And you can not ask for that cipher, depending on client.
 
Old 08-12-2022, 09:12 AM   #4
Turbocapitalist
LQ Guru
 
Registered: Apr 2005
Distribution: Linux Mint, Devuan, OpenBSD
Posts: 7,313
Blog Entries: 3

Rep: Reputation: 3723Reputation: 3723Reputation: 3723Reputation: 3723Reputation: 3723Reputation: 3723Reputation: 3723Reputation: 3723Reputation: 3723Reputation: 3723Reputation: 3723
Quote:
Originally Posted by 1s440 View Post
Can anyone suggests?
Suggestion: Update the server post haste.
 
Old 08-17-2022, 08:56 PM   #5
sundialsvcs
LQ Guru
 
Registered: Feb 2004
Location: SE Tennessee, USA
Distribution: Gentoo, LFS
Posts: 10,662
Blog Entries: 4

Rep: Reputation: 3943Reputation: 3943Reputation: 3943Reputation: 3943Reputation: 3943Reputation: 3943Reputation: 3943Reputation: 3943Reputation: 3943Reputation: 3943Reputation: 3943
Quote:
Originally Posted by Turbocapitalist View Post
Suggestion: Update the server post haste.
Entirely agree. The server appears to be offering to conduct the conversation using a cipher that is considerably out-of-date by present standards. But also, be sure that the client is also as up-to-date as possible. Both parties need to always be "singing from the latest songbook."
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
[SOLVED] Kali 3.12 no iNET connectivity >> boot 3.7 >> connectivity = fine bostonsean Linux - Networking 6 04-19-2014 05:41 PM
Outgoing Connectivity problems. Incoming connectivity fine Fionnbharr Linux - Newbie 1 10-02-2008 12:51 PM
connectivity or not connectivity munkie_poo Linux - Newbie 0 05-07-2004 06:47 AM
SSH connectivity issues wvrhlu Linux - Software 11 04-01-2003 08:59 PM
AT&T Broadband Connectivity Issues toast Linux - Newbie 1 10-14-2002 04:20 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Server

All times are GMT -5. The time now is 03:04 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration