1
21.7 Legacy Series / Re: OpenSSH does not start after updatding to 21.7.5
« on: December 15, 2021, 11:53:17 am »
Hi Franco,
thank you for the suggestion. I'm not aware to have changed something to override defaults (in this area), but at the same time, being pretty new to firewalls and especially opnsense, I have been doing guesswork to get things working the way I want.
Anyway, after some searching I've found System -> Settings -> Administration -> Key Exchange Algorithms which was configured to accept the entire list, except for the last entry.
After disabling all methods with "SHA1" in their names and saving, OpenSSH managed to start up again.
Note that disabling everything with SHA1 in their names is again a wild guess based on the fact that SHA1 isn't considered the most secure algorithm any more. It could be OK in combination with other things though. Sometimes wild guesses work :-)
Thank you again for the valuable hint!
Best regards,
Ronald
thank you for the suggestion. I'm not aware to have changed something to override defaults (in this area), but at the same time, being pretty new to firewalls and especially opnsense, I have been doing guesswork to get things working the way I want.
Anyway, after some searching I've found System -> Settings -> Administration -> Key Exchange Algorithms which was configured to accept the entire list, except for the last entry.
After disabling all methods with "SHA1" in their names and saving, OpenSSH managed to start up again.
Note that disabling everything with SHA1 in their names is again a wild guess based on the fact that SHA1 isn't considered the most secure algorithm any more. It could be OK in combination with other things though. Sometimes wild guesses work :-)
Thank you again for the valuable hint!
Best regards,
Ronald