HMC – SSH Server CBC Mode Ciphers Enabled – SSH Weak MAC Algorithms Enabled issue

0
1096

information security department sent “SSH Server CBC Mode Ciphers Enabled” and “SSH Server CBC Mode Ciphers Enabled” issues on Hardware Management Console( HMC ) .How can I fix this?

First, you can learn current configuration below scripts.

[email protected]:~> lshmcencr -c ssh -t c
"curr_encryptions=aes128-cbc,aes128-ctr,[email protected],aes192-cbc,aes192-ctr,aes256-cbc,aes256-ctr,[email protected],arcfour,arcfour128,arcfour256"
[email protected]:~> lshmcencr -c sshmac -t c
"curr_encryptions=hmac-ripemd160,[email protected],hmac-sha1,[email protected],hmac-sha2-256,[email protected],hmac-sha2-512,[email protected],[email protected],[email protected],[email protected],[email protected]"

I want to use “arcfour,arcfour128,arcfour256 cipher” and “hmac-sha1,[email protected],hmac-ripemd160” macs.So I deleted others currenct configurations.

Delete ciphers:

chhmcencr -c ssh -o r -e aes128-cbc
chhmcencr -c ssh -o r -e [email protected]
chhmcencr -c ssh -o r -e aes192-cbc
chhmcencr -c ssh -o r -e aes256-cbc
chhmcencr -c ssh -o r -e [email protected]
chhmcencr -c ssh -o r -e arcfour
chhmcencr -c ssh -o r -e arcfour128
chhmcencr -c ssh -o r -e arcfour256

After that:

[email protected]:~> lshmcencr -c ssh -t c
"curr_encryptions=aes128-ctr,aes192-ctr,aes256-ctr"

chhmcencr -c sshmac -o r -e [email protected]
chhmcencr -c sshmac -o r -e [email protected]
chhmcencr -c sshmac -o r -e hmac-sha2-256
chhmcencr -c sshmac -o r -e [email protected]
chhmcencr -c sshmac -o r -e hmac-sha2-512
chhmcencr -c sshmac -o r -e [email protected]
chhmcencr -c sshmac -o r -e [email protected]
chhmcencr -c sshmac -o r -e [email protected]
chhmcencr -c sshmac -o r -e [email protected]

Finally.Thanks OK!
[email protected]:~> lshmcencr -c sshmac -t c
"curr_encryptions=hmac-ripemd160,hmac-sha1,[email protected]"

After that you cannot connect your HMC because this command stop your ssh connectivity.So you should login your HMC and start your Remote Command Execution section on your HMC settings.

LEAVE A REPLY

Please enter your comment!
Please enter your name here

This site uses Akismet to reduce spam. Learn how your comment data is processed.