<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Netapp SSH not working in ONTAP Discussions</title>
    <link>https://community.netapp.com/t5/ONTAP-Discussions/Netapp-SSH-not-working/m-p/157469#M35748</link>
    <description>&lt;P&gt;Hello Expert,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;we recently installed a client Host SuSE Enterprise Linux 15. We noticed that from this host , we are unable to do ssh onto Netapp Storage. Netapp Ontap Release is 8.1.4P7 7-Mode.&lt;/P&gt;
&lt;P&gt;The error says,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&amp;gt;ssh&amp;nbsp; NetappServer&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;ssh_dispatch_run_fatal: Connection to 192.&lt;SPAN style="font-family: inherit;"&gt;XXX.XXX.XXX port 22: Invalid key length&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&amp;gt; ssh&amp;nbsp; NetappServer -v&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;OpenSSH_7.9p1, OpenSSL 1.1.0i-fips 14 Aug 2018&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;debug1: Reading configuration data /root/.ssh/config&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;debug1: /root/.ssh/config line 1: Applying options for NetappServer&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;debug1: /root/.ssh/config line 4: Deprecated option "cipher"&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;debug1: Reading configuration data /etc/ssh/ssh_config&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;debug1: /etc/ssh/ssh_config line 20: Applying options for *&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;debug1: Connecting to NetappServer [192.&lt;SPAN style="font-family: inherit;"&gt;XXX.XXX.XXX&lt;/SPAN&gt;] port 22.&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;debug1: Connection established.&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;debug1: identity file /root/.ssh/id_rsa_2048 type 0&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;debug1: identity file /root/.ssh/id_rsa_2048-cert type -1&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;debug1: Local version string SSH-2.0-OpenSSH_7.9&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;debug1: Remote protocol version 2.0, remote software version Data ONTAP SSH 1.0&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;debug1: no match: Data ONTAP SSH 1.0&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;debug1: Authenticating to NetappServer:22 as 'root'&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;debug1: SSH2_MSG_KEXINIT sent&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;debug1: SSH2_MSG_KEXINIT received&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;debug1: kex: algorithm: diffie-hellman-group1-sha1&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;debug1: kex: host key algorithm: ssh-rsa&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;debug1: kex: server-&amp;gt;client cipher: 3des-cbc MAC: hmac-sha1 compression: none&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;debug1: kex: client-&amp;gt;server cipher: 3des-cbc MAC: hmac-sha1 compression: none&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;debug1: kex: diffie-hellman-group1-sha1 need=24 dh_need=20&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;debug1: kex: diffie-hellman-group1-sha1 need=24 dh_need=20&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;debug1: sending SSH2_MSG_KEXDH_INIT&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;debug1: expecting SSH2_MSG_KEXDH_REPLY&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;ssh_dispatch_run_fatal: Connection to 192.&lt;SPAN style="font-family: inherit;"&gt;XXX.XXX.XXX&amp;nbsp;&lt;/SPAN&gt; port 22: Invalid key length&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It says there is mismarch in SSH Keys or so. You guys have faced this problem? Do I have to upgrade netapp ssh version?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please guide me to positive direction.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks in advance.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Admin&lt;/P&gt;</description>
    <pubDate>Wed, 04 Jun 2025 11:02:50 GMT</pubDate>
    <dc:creator>siemensocs</dc:creator>
    <dc:date>2025-06-04T11:02:50Z</dc:date>
    <item>
      <title>Netapp SSH not working</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Netapp-SSH-not-working/m-p/157469#M35748</link>
      <description>&lt;P&gt;Hello Expert,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;we recently installed a client Host SuSE Enterprise Linux 15. We noticed that from this host , we are unable to do ssh onto Netapp Storage. Netapp Ontap Release is 8.1.4P7 7-Mode.&lt;/P&gt;
&lt;P&gt;The error says,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&amp;gt;ssh&amp;nbsp; NetappServer&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;ssh_dispatch_run_fatal: Connection to 192.&lt;SPAN style="font-family: inherit;"&gt;XXX.XXX.XXX port 22: Invalid key length&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&amp;gt; ssh&amp;nbsp; NetappServer -v&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;OpenSSH_7.9p1, OpenSSL 1.1.0i-fips 14 Aug 2018&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;debug1: Reading configuration data /root/.ssh/config&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;debug1: /root/.ssh/config line 1: Applying options for NetappServer&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;debug1: /root/.ssh/config line 4: Deprecated option "cipher"&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;debug1: Reading configuration data /etc/ssh/ssh_config&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;debug1: /etc/ssh/ssh_config line 20: Applying options for *&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;debug1: Connecting to NetappServer [192.&lt;SPAN style="font-family: inherit;"&gt;XXX.XXX.XXX&lt;/SPAN&gt;] port 22.&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;debug1: Connection established.&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;debug1: identity file /root/.ssh/id_rsa_2048 type 0&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;debug1: identity file /root/.ssh/id_rsa_2048-cert type -1&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;debug1: Local version string SSH-2.0-OpenSSH_7.9&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;debug1: Remote protocol version 2.0, remote software version Data ONTAP SSH 1.0&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;debug1: no match: Data ONTAP SSH 1.0&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;debug1: Authenticating to NetappServer:22 as 'root'&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;debug1: SSH2_MSG_KEXINIT sent&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;debug1: SSH2_MSG_KEXINIT received&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;debug1: kex: algorithm: diffie-hellman-group1-sha1&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;debug1: kex: host key algorithm: ssh-rsa&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;debug1: kex: server-&amp;gt;client cipher: 3des-cbc MAC: hmac-sha1 compression: none&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;debug1: kex: client-&amp;gt;server cipher: 3des-cbc MAC: hmac-sha1 compression: none&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;debug1: kex: diffie-hellman-group1-sha1 need=24 dh_need=20&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;debug1: kex: diffie-hellman-group1-sha1 need=24 dh_need=20&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;debug1: sending SSH2_MSG_KEXDH_INIT&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;debug1: expecting SSH2_MSG_KEXDH_REPLY&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;ssh_dispatch_run_fatal: Connection to 192.&lt;SPAN style="font-family: inherit;"&gt;XXX.XXX.XXX&amp;nbsp;&lt;/SPAN&gt; port 22: Invalid key length&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It says there is mismarch in SSH Keys or so. You guys have faced this problem? Do I have to upgrade netapp ssh version?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please guide me to positive direction.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks in advance.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Admin&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jun 2025 11:02:50 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Netapp-SSH-not-working/m-p/157469#M35748</guid>
      <dc:creator>siemensocs</dc:creator>
      <dc:date>2025-06-04T11:02:50Z</dc:date>
    </item>
    <item>
      <title>Re: Netapp SSH not working</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Netapp-SSH-not-working/m-p/157470#M35749</link>
      <description>&lt;P&gt;You should re-run&amp;nbsp;&lt;/P&gt;
&lt;P&gt;secureadmin ssh setup -f&lt;/P&gt;
&lt;P&gt;and use a loner key length (like 2048)&lt;/P&gt;</description>
      <pubDate>Thu, 02 Jul 2020 14:25:08 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Netapp-SSH-not-working/m-p/157470#M35749</guid>
      <dc:creator>TMACMD</dc:creator>
      <dc:date>2020-07-02T14:25:08Z</dc:date>
    </item>
    <item>
      <title>Re: Netapp SSH not working</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Netapp-SSH-not-working/m-p/157471#M35750</link>
      <description>&lt;P&gt;I didnt get this. Where should I run this? On Ontap itself? What does it actually do?&lt;/P&gt;</description>
      <pubDate>Thu, 02 Jul 2020 14:29:06 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Netapp-SSH-not-working/m-p/157471#M35750</guid>
      <dc:creator>siemensocs</dc:creator>
      <dc:date>2020-07-02T14:29:06Z</dc:date>
    </item>
    <item>
      <title>Re: Netapp SSH not working</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Netapp-SSH-not-working/m-p/157472#M35751</link>
      <description>&lt;P&gt;Ontap command. Specifically 7-mode which you have.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;it recreates the ontap side ssh key to be longer. You probably currently have a 1024 bit key&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;run the command and create a 2048 bit key&lt;/P&gt;</description>
      <pubDate>Thu, 02 Jul 2020 14:41:58 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Netapp-SSH-not-working/m-p/157472#M35751</guid>
      <dc:creator>TMACMD</dc:creator>
      <dc:date>2020-07-02T14:41:58Z</dc:date>
    </item>
    <item>
      <title>Re: Netapp SSH not working</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Netapp-SSH-not-working/m-p/157482#M35759</link>
      <description>&lt;P&gt;Aah Ok. But does it mean the other&amp;nbsp; SLES12 or SuSE10 clients would not be able to ssh to Netapp Filer? Only SLES15 will be able to ssh to Filer? Becaue at the moment the other clients can SSH to Netapp Filer&amp;nbsp;without any problems .&lt;/P&gt;</description>
      <pubDate>Fri, 03 Jul 2020 06:52:16 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Netapp-SSH-not-working/m-p/157482#M35759</guid>
      <dc:creator>siemensocs</dc:creator>
      <dc:date>2020-07-03T06:52:16Z</dc:date>
    </item>
    <item>
      <title>Re: Netapp SSH not working</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Netapp-SSH-not-working/m-p/157491#M35764</link>
      <description>&lt;P&gt;They other Linux boxes should&amp;nbsp;continue to work. The newer hosts likely have harder restrictions for SSH.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;what will happen is that the keys will change and you will get a message to that effect the next time you use SSH. You simply need to remove the offending entry in the known_hosts file. Then try again&lt;/P&gt;</description>
      <pubDate>Fri, 03 Jul 2020 12:26:37 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Netapp-SSH-not-working/m-p/157491#M35764</guid>
      <dc:creator>TMACMD</dc:creator>
      <dc:date>2020-07-03T12:26:37Z</dc:date>
    </item>
    <item>
      <title>Re: Netapp SSH not working</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Netapp-SSH-not-working/m-p/157501#M35765</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I did the following but now I am not able to ssh from Any Linux hosts&amp;nbsp; &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;bwgb198&amp;gt; secureadmin disable ssh&lt;BR /&gt;bwgb198&amp;gt; secureadmin setup -f ssh&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please enter the size of host key for ssh1.x protocol [768] :&lt;/P&gt;
&lt;P&gt;Please enter the size of server key for ssh1.x protocol [512] :&lt;BR /&gt;Please enter the size of host keys for ssh2.0 protocol [768] :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;After this I could not ssh from any Linuy hosts. Luckily I still have my first ssh login onto Ontap so I can try few more times before the login times out. Opps thats getting critical now. How should I set the above three values. I tries already few options like 768, 2048 , 2048 but not sure what combination will work for me. Please help.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 06 Jul 2020 07:56:35 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Netapp-SSH-not-working/m-p/157501#M35765</guid>
      <dc:creator>siemensocs</dc:creator>
      <dc:date>2020-07-06T07:56:35Z</dc:date>
    </item>
    <item>
      <title>Re: Netapp SSH not working</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Netapp-SSH-not-working/m-p/157681#M35825</link>
      <description>&lt;P&gt;below is what i use to use.&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;Please enter the size of host key for ssh1.x protocol [2048] :
Please enter the size of server key for ssh1.x protocol [1024] :
Please enter the size of host keys(rsa key) for ssh2.0 protocol [2048] :
Please enter the size of host keys(dsa key) for ssh2.0 protocol [1024] :
Please enter the size of host keys(ecdsa key) for ssh2.0 protocol [256] :
Please enter the size of host keys(ed25519 key) for ssh2.0 protocol [2048] :&lt;/LI-CODE&gt;</description>
      <pubDate>Fri, 10 Jul 2020 06:28:19 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Netapp-SSH-not-working/m-p/157681#M35825</guid>
      <dc:creator>Mjizzini</dc:creator>
      <dc:date>2020-07-10T06:28:19Z</dc:date>
    </item>
  </channel>
</rss>

