L.S.
After upgrading to F36 I have problems accessing the F36 server with ssh form OpenVMS machines. The problem is probably (again) that OpenVMS only supports "old" keys. In the past I added the following to my sshd_config:
Ciphers +aes128-cbc
MACs umac-64-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-256-etm@openssh. com,hmac-sha2-512-etm@openssh.com,umac-64@openssh.com,umac-128@openssh.com,hmac- sha2-256,hmac-sha2-512,hmac-md5,hmac-md5-96,hmac-sha1,hmac-sha1-96
KexAlgorithms curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384 ,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group-ex change-sha1,diffie-hellman-group14-sha1,diffie-hellman-group1-sha1
This worked in F35. Probably some encryptions are disabled. How can I enable them again?
Regards Jouk
Pax, vel iniusta, utilior est quam iustissimum bellum. (free after Marcus Tullius Cicero (106 b.Chr.-46 b.Chr.) Epistularum ad Atticum 7.1.4.3)
Touch not the cat bot a glove
------------------------------------------------------------------------------<
Jouk Jansen joukj@hrem.nano.tudelft.nl
Technische Universiteit Delft tttttttttt uu uu ddddddd Kavli Institute of Nanoscience tttttttttt uu uu dd dd Nationaal centrum voor HREM tt uu uu dd dd Lorentzweg 1 tt uu uu dd dd 2628 CJ Delft tt uu uu dd dd Nederland tt uu uu dd dd tel. +31-15-2782272 tt uuuuuuu ddddddd
------------------------------------------------------------------------------<
On Thu, 12 May 2022 08:43:39 +0200 (CEST) "Jouk Jansen" joukj@hrem.nano.tudelft.nl wrote:
L.S.
After upgrading to F36 I have problems accessing the F36 server with ssh form OpenVMS machines. The problem is probably (again) that OpenVMS only supports "old" keys. In the past I added the following
[snip]
This worked in F35. Probably some encryptions are disabled. How can I enable them again?
This might work update-crypto-policies --set LEGACY
update-crypto-policies --set DEFAULT will return to hardened policies.
The reason it might not work is if the policies have been removed instead of just turned off. Then you would have to download the f35 src.rpm from koji, build it on your machine, downgrade the f36 version, and then blocklist it in /etc/dnf/dnf.conf so it doesn't get upgraded.
Setting the crypto policies dis not help.
So I will have to install the f35 version.
Jouk