[Labs-l] sshd config: using newer ciphers and protocols

Platonides platonides at gmail.com
Sun May 24 20:09:28 UTC 2015


On 24/05/15 00:26, Merlijn van Deen wrote:
> We have temporarily reverted this for Tool Labs, as we've found a few 
> more situations where people are unable to log in (NetBSD ssh (not sure 
> about the version, but not that old), Debian Squeeze, some versions of 
> git bash on windows, PuTTY < 0.62). Of course, we'd prefer to use more 
> secure ciphers, so we'll try to find a solution where we find a balance 
> between security and usability.
> 
> Best,
> Merlijn

Note that as long as the user has a modern client, it will prefer the secure ciphers.
(and ssh doesn't allow a cipher selection downgrade)



More information about the Labs-l mailing list