<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: unable to SSH without specifying algorithm in ONTAP Discussions</title>
    <link>https://community.netapp.com/t5/ONTAP-Discussions/unable-to-SSH-without-specifying-algorithm/m-p/128197#M27774</link>
    <description>&lt;P&gt;Yes, I've seen this page before, taht's how I found out how to still ssh into the shelf but it also says that its the legacy system (netapp in this case) that doesn't support a higher encryption level. Is there not a way to enable a higher encryption level on the shelf?&lt;/P&gt;</description>
    <pubDate>Thu, 16 Feb 2017 17:17:24 GMT</pubDate>
    <dc:creator>gadgetvirtuoso</dc:creator>
    <dc:date>2017-02-16T17:17:24Z</dc:date>
    <item>
      <title>unable to SSH without specifying algorithm</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/unable-to-SSH-without-specifying-algorithm/m-p/128163#M27762</link>
      <description>&lt;P&gt;After completing the recommended changes to our filer we can't just ssh to either controller without specifiying the algorithm to use.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://kb.netapp.com/support/s/article/ka31A0000000yGnQAI/how-to-disable-sslv2-and-sslv3-in-data-ontap-for-cve-2016-0800-and-cve-2014-3566?language=en_US" target="_blank"&gt;https://kb.netapp.com/support/s/article/ka31A0000000yGnQAI/how-to-disable-sslv2-and-sslv3-in-data-ontap-for-cve-2016-0800-and-cve-2014-3566?language=en_US&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;FAS2220 8.1.1 7-mode&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you try SSH to either controller on the shelf you see the following&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Unable to negotiate with IP_ADDRESS&amp;nbsp;port 22: no matching key exchange method found. Their offer: diffie-hellman-group1-sha1&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;However using this option works 100%&lt;/P&gt;
&lt;P&gt;&amp;gt; ssh -oKexAlgorithms=+diffie-hellman-group1-sha1 user@filer&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We're mostly a Mac shop so I usually SSH from Mac, currently 10.12.3&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Options ssh&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;ssh.access *&lt;BR /&gt;ssh.enable on&lt;BR /&gt;ssh.idle.timeout 600&lt;BR /&gt;ssh.passwd_auth.enable on&lt;BR /&gt;ssh.port 22&lt;BR /&gt;ssh.pubkey_auth.enable on&lt;BR /&gt;ssh1.enable off&lt;BR /&gt;ssh2.enable on&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jun 2025 15:26:50 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/unable-to-SSH-without-specifying-algorithm/m-p/128163#M27762</guid>
      <dc:creator>gadgetvirtuoso</dc:creator>
      <dc:date>2025-06-04T15:26:50Z</dc:date>
    </item>
    <item>
      <title>Re: unable to SSH without specifying algorithm</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/unable-to-SSH-without-specifying-algorithm/m-p/128169#M27763</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for contacting NetApp community.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I see this issue is specific to MAC OS &lt;SPAN&gt;Sierra&amp;nbsp;&lt;/SPAN&gt;10.12 and Open SSH. I found a useful link which may help you to fix the issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.openssh.com/legacy.html" target="_self"&gt;https://www.openssh.com/legacy.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Nayab&lt;/P&gt;</description>
      <pubDate>Thu, 16 Feb 2017 05:50:34 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/unable-to-SSH-without-specifying-algorithm/m-p/128169#M27763</guid>
      <dc:creator>NAYABSK</dc:creator>
      <dc:date>2017-02-16T05:50:34Z</dc:date>
    </item>
    <item>
      <title>Re: unable to SSH without specifying algorithm</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/unable-to-SSH-without-specifying-algorithm/m-p/128197#M27774</link>
      <description>&lt;P&gt;Yes, I've seen this page before, taht's how I found out how to still ssh into the shelf but it also says that its the legacy system (netapp in this case) that doesn't support a higher encryption level. Is there not a way to enable a higher encryption level on the shelf?&lt;/P&gt;</description>
      <pubDate>Thu, 16 Feb 2017 17:17:24 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/unable-to-SSH-without-specifying-algorithm/m-p/128197#M27774</guid>
      <dc:creator>gadgetvirtuoso</dc:creator>
      <dc:date>2017-02-16T17:17:24Z</dc:date>
    </item>
    <item>
      <title>Re: unable to SSH without specifying algorithm</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/unable-to-SSH-without-specifying-algorithm/m-p/128216#M27778</link>
      <description>&lt;P&gt;This system is running ONTAP 8.1.1 in 7-Mode (released in 2012), which is no longer supported by NetApp. While support is still available for 7-Mode ONTAP (if running 8.1.4, or 8.2.4), no new feature enhancement&amp;nbsp;work is being undertaken on the platform, and as such, there is no fix planned for this issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Our suggested fix is to add in your client's&amp;nbsp;~/.ssh/config file:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;Host somehost.example.org
KexAlgorithms +diffie-hellman-group1-sha1&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Alternatively, with a valid support contract (and, unfortunately, migrating all the data off and back on, and the addition of a 10Gb Mezzanine card if not already present..), this system can be reformatted to run ONTAP 9.1, which is a Clustered ONTAP only release, and which fixes this issue, but it is by no means the easy option.&lt;/P&gt;</description>
      <pubDate>Thu, 16 Feb 2017 23:34:11 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/unable-to-SSH-without-specifying-algorithm/m-p/128216#M27778</guid>
      <dc:creator>AlexDawson</dc:creator>
      <dc:date>2017-02-16T23:34:11Z</dc:date>
    </item>
  </channel>
</rss>

