Learn how to a build a cloud-first strategyRegister Now

x
?
Solved

SSH - How to Disable CBC Mode Cipher Encryption and Enable CTR or GCM Cipher MOde Encryption?

Posted on 2015-01-13
4
Medium Priority
?
7,575 Views
Last Modified: 2015-01-14
Hello Experts - Curious if someone could instruct me how to disable CBC mode cipher encryption, and enable CTR or GCM cipher mode encryption.  Any help or suggestions are greatly appreciated.
0
Comment
Question by:itsmevic
  • 2
  • 2
4 Comments
 
LVL 23

Accepted Solution

by:
savone earned 2000 total points
ID: 40548256
You can simply add the ciphers option in the sshd_config by adding the following line:

Ciphers aes128-ctr,aes192-ctr,aes256-ctr
0
 

Author Closing Comment

by:itsmevic
ID: 40548794
Awesome, thank you!
0
 

Author Comment

by:itsmevic
ID: 40548851
I'm assuming I can add that line anywhere in the sshd_config file?   Is there a command to save my work?   Pardon my ignorance, I'm new with Linux.

Basically, how I'm going into it now is that I'm logging in as Root, then doing a:  

# vim /etc/ssh/sshd_config it will open and ask me if I want to Open, Delete, Edit, etc the file.  I choose "E" for Edit, then I went in and added Ciphers aes128-ctr,aes192-ctr,aes256-ctr  at the very bottom of the config file, then X'd out of the terminal window, thinking it would save my changes but I'm not sure if it is or not.  When I try and go back into the config file it's telling me that it's detected a SWP file of the config file.
0
 
LVL 23

Expert Comment

by:savone
ID: 40549311
You have to write the file first before closing the Window.

After making the edit hit escape to get out if edit mode. Then type :wq and hit enter to save.
0

Featured Post

Independent Software Vendors: We Want Your Opinion

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

The purpose of this article is to show how we can create Linux Mint virtual machine using Oracle Virtual Box. To install Linux Mint we have to download the ISO file from its website i.e. http://www.linuxmint.com. Once you open the link you will see …
I have written articles previously comparing SARDU and YUMI.  I also included a couple of lines about Easy2boot (easy2boot.com).  I have now been using, and enjoying easy2boot as my sole multiboot utility for some years and realize that it deserves …
Learn how to navigate the file tree with the shell. Use pwd to print the current working directory: Use ls to list a directory's contents: Use cd to change to a new directory: Use wildcards instead of typing out long directory names: Use ../ to move…
Connecting to an Amazon Linux EC2 Instance from Windows Using PuTTY.
Suggested Courses
Course of the Month21 days, 5 hours left to enroll

810 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question