CCS Supported KEX/MACs for SSH
search cancel

CCS Supported KEX/MACs for SSH

book

Article ID: 210658

calendar_today

Updated On: 11-03-2023

Products

Control Compliance Suite Control Compliance Suite Standards Server

Issue/Introduction

Control Compliance Suite (CCS)

What key exchange algorithms and MAC (message authentication code) are supported in CCS?

Environment

CCS 12.6.x

Resolution

Note: Empty value in "Supported Since" denotes that the algorithm is supported by CCS, but we don't have information from which SCU those were supported.  Those are added more than a decade before and always available.

 

Key Exchange Algorithm
Supported Since
rsa1024-sha1  
rsa2048-sha256  
diffie-hellman-group1-sha1  
diffie-hellman-group-exchange-sha1  
diffie-hellman-group14-sha1  
diffie-hellman-group-exchange-sha256 SCU 2017-3
diffie-hellman-group14-sha256 SCU 2019-2
diffie-hellman-group16-sha512 SCU 2019-2
diffie-hellman-group18-sha512 SCU 2019-2
curve25519-sha256@libssh.org SCU 2019-2
ecdh-sha2-nistp256 SCU 2019-2
ecdh-sha2-nistp384 SCU 2019-2
ecdh-sha2-nistp521 SCU 2019-2


MAC
Supported Since
hmac-md5  
hmac-sha1  
hmac-sha2-256 SCU 2017-3
hmac-sha2-512 SCU 2019-2
hmac-sha2-256-etm@openssh.com SCU 2022-3
hmac-sha2-512-etm@openssh.com SCU 2022-3
hmac-sha1-etm@openssh.com SCU 2022-3
hmac-md5-etm@openssh.com SCU 2022-3
 
HostKey Algorithm
Supported Since
ssh-dss  
ssh-rsa  
rsa-sha2-256 SCU 2021-1
Cipher
Supported Since

des-cbc

 
des-cbc@ssh.com  
3des-cbc  
blowfish-cbc  
arcfour128  
arcfour256  
aes256-ctr  
aes256-cbc  
rijndael-cbc@lysator.liu.se  
aes192-ctr  
aes192-cbc  
aes128-ctr  
aes128-cbc  

 

PubKeyAcceptedAlgorithms 
Supported Since
ecdsa-sha2-nistp256 SCU 2022-3
ecdsa-sha2-nistp384 SCU 2022-3
ecdsa-sha2-nistp521 SCU 2022-3