<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ONTAP 9.4 SSH Public Key Access Broken ( key type ssh-rsa not in PubkeyAcceptedKeyTypes) in ONTAP Discussions</title>
    <link>https://community.netapp.com/t5/ONTAP-Discussions/ONTAP-9-4-SSH-Public-Key-Access-Broken-key-type-ssh-rsa-not-in/m-p/147637#M32844</link>
    <description>&lt;P&gt;&lt;a href="https://community.netapp.com/t5/user/viewprofilepage/user-id/53461"&gt;@parkea2&lt;/a&gt;&amp;nbsp;&amp;nbsp;Let me know if you are still looking for the solution, i will help you find an expert who can answer to your query.&lt;/P&gt;</description>
    <pubDate>Tue, 02 Apr 2019 07:52:32 GMT</pubDate>
    <dc:creator>RajeshPanda</dc:creator>
    <dc:date>2019-04-02T07:52:32Z</dc:date>
    <item>
      <title>ONTAP 9.4 SSH Public Key Access Broken ( key type ssh-rsa not in PubkeyAcceptedKeyTypes)</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/ONTAP-9-4-SSH-Public-Key-Access-Broken-key-type-ssh-rsa-not-in/m-p/146898#M32690</link>
      <description>&lt;P&gt;One of my powers users as role based restricted access to the FAS using a ssh-rsa 2048 public key only. &amp;nbsp; This previously worked&amp;nbsp;OK we started at ONTAP 9.1, then 9.2 and &amp;nbsp;until recently was &amp;nbsp;on 9.3P4 all working OK for about 2 years.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The Problem:&lt;/P&gt;
&lt;P&gt;The user can nolonger access the FAS using the pubkey. &amp;nbsp;I suspect but I &amp;nbsp;cannot be certain this broke when we updated to&lt;/P&gt;
&lt;P&gt;9.4.P3 in December 2018. &amp;nbsp;The error is: &amp;nbsp;key type ssh-rsa not in PubkeyAcceptedKeyTypes . &amp;nbsp; I also tried a new key ssh-ed25519 both have the same error. &amp;nbsp;See below:&lt;/P&gt;
&lt;P&gt;--------------&lt;/P&gt;
&lt;P&gt;00000018.001cc78e 0dcc3fa7 Sat Mar 02 2019 12:04:13 +00:00 [auth_sshd:info:8218] userauth_pubkey: key type ssh-rsa not in PubkeyAcceptedKeyTypes [preauth]&lt;BR /&gt;00000018.001cc78f 0dcc3fa7 Sat Mar 02 2019 12:04:13 +00:00 [auth_sshd:info:8218] userauth_pubkey: key type ssh-ed25519 not in PubkeyAcceptedKeyTypes&lt;/P&gt;
&lt;P&gt;--------------&lt;/P&gt;
&lt;P&gt;The ssh keys are good, I checked the fingerprint at both end and tested to other servers (Linux / AIX) both worked with the keys OK. &amp;nbsp; Also SSH password based access to the FAS works fine. &amp;nbsp;The MFA second authentication method is set to none.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Question:&lt;/P&gt;
&lt;P&gt;1) As anybody seen this before. &amp;nbsp;I am struggling to get any good hits googling using the error message for ONTAP.&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; Linux hits indicate sshd_config can be updated to allow key types removed at later SSH 7.x levels. For example to&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp;allow ssh-dss which was removed from the defaults at openssh 7.x.&lt;/P&gt;
&lt;P&gt;2) I cannot see any means of querying or modifying the ONTAP (FAS) settings for&amp;nbsp;PubkeyAcceptedKeyTypes.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am able to log a support ticket via the NETAPP Partner IBM who provide our L1/L2 support before it esculates to NETAPP directly via IBM if they cannot resolve it. &amp;nbsp;However I want to ask in the community first and potentially build a stronger testcase to demonstrate the problem.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jun 2025 12:47:16 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/ONTAP-9-4-SSH-Public-Key-Access-Broken-key-type-ssh-rsa-not-in/m-p/146898#M32690</guid>
      <dc:creator>parkea2</dc:creator>
      <dc:date>2025-06-04T12:47:16Z</dc:date>
    </item>
    <item>
      <title>Re: ONTAP 9.4 SSH Public Key Access Broken ( key type ssh-rsa not in PubkeyAcceptedKeyTypes)</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/ONTAP-9-4-SSH-Public-Key-Access-Broken-key-type-ssh-rsa-not-in/m-p/147637#M32844</link>
      <description>&lt;P&gt;&lt;a href="https://community.netapp.com/t5/user/viewprofilepage/user-id/53461"&gt;@parkea2&lt;/a&gt;&amp;nbsp;&amp;nbsp;Let me know if you are still looking for the solution, i will help you find an expert who can answer to your query.&lt;/P&gt;</description>
      <pubDate>Tue, 02 Apr 2019 07:52:32 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/ONTAP-9-4-SSH-Public-Key-Access-Broken-key-type-ssh-rsa-not-in/m-p/147637#M32844</guid>
      <dc:creator>RajeshPanda</dc:creator>
      <dc:date>2019-04-02T07:52:32Z</dc:date>
    </item>
    <item>
      <title>Re: ONTAP 9.4 SSH Public Key Access Broken ( key type ssh-rsa not in PubkeyAcceptedKeyTypes)</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/ONTAP-9-4-SSH-Public-Key-Access-Broken-key-type-ssh-rsa-not-in/m-p/147647#M32848</link>
      <description>&lt;P&gt;Only got this fully resolved yesterday. It appears a change was made at 9.4 P3 that stops RSA and ED25519 keys&lt;/P&gt;
&lt;P&gt;from working to the admin SVM. &amp;nbsp;Switching to&amp;nbsp;ECDSA keys resolved the problem.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Message seen in log was:&lt;/P&gt;
&lt;P&gt;00000018.0025399a 0f15eef9 Wed Mar 27 2019 12:14:42 +00:00 [auth_sshd:info:29433] userauth_pubkey: key type ssh-ed25519 not in PubkeyAcceptedKeyTypes [preauth]&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 02 Apr 2019 08:09:40 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/ONTAP-9-4-SSH-Public-Key-Access-Broken-key-type-ssh-rsa-not-in/m-p/147647#M32848</guid>
      <dc:creator>parkea2</dc:creator>
      <dc:date>2019-04-02T08:09:40Z</dc:date>
    </item>
  </channel>
</rss>

