<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: &amp;quot;security ssh&amp;quot; configuration in ONTAP Discussions</title>
    <link>https://community.netapp.com/t5/ONTAP-Discussions/quot-security-ssh-quot-configuration/m-p/164066#M37549</link>
    <description>&lt;P&gt;Ah, i found something in the messages.log:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;sshd 65444 - - fatal: /etc/ssh/sshd_config line 102: Bad SSH2 mac spec 'hmac-sha2-256,hmac-sha2-512,hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,umac-128@openssh.com-etm,umac-128,hmac-sha1,hmac-sha1-96,hmac-sha1-etm@openssh.com,hmac-sha1-96-etm@openssh.com,hmac-md5,hmac-md5-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,umac-64-etm@openssh.com'.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This line i got when trying to login. So i will compare later with a untouched system...&lt;/P&gt;</description>
    <pubDate>Wed, 17 Feb 2021 08:01:03 GMT</pubDate>
    <dc:creator>sraudonis</dc:creator>
    <dc:date>2021-02-17T08:01:03Z</dc:date>
    <item>
      <title>"security ssh" configuration</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/quot-security-ssh-quot-configuration/m-p/164052#M37544</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;a customer wrote to me that the NetApp supports some weak ssh MAC and Encryption algorithms or Cyphers.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So i tested with "security ssh remove" to remove all with CBC, SHA1 und MD5.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I tested the access after that commnds and got no problems.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But now, one week later i cant login via SSH to the NetApp, i got only "Remote side unexpectedly closed network connection".&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So i inserted all what i remved again, but i still can't login.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When it takes up to a week to get active after removing, how log does it take to get active after inserting again?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is here a commend to restart the SSH?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm using ONTAP 9.8P1.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kind regards&lt;/P&gt;&lt;P&gt;Stefan&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jun 2025 10:34:58 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/quot-security-ssh-quot-configuration/m-p/164052#M37544</guid>
      <dc:creator>sraudonis</dc:creator>
      <dc:date>2025-06-04T10:34:58Z</dc:date>
    </item>
    <item>
      <title>Re: "security ssh" configuration</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/quot-security-ssh-quot-configuration/m-p/164060#M37547</link>
      <description>&lt;P&gt;There are 2 KB with similar issues:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Unable to connect via SSH to node/cluster management LIF&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://kb.netapp.com/Advice_and_Troubleshooting/Data_Storage_Software/ONTAP_OS/Unable_to_connect_via_SSH_to_node_cluster_management_LIF" target="_blank" rel="noopener"&gt;https://kb.netapp.com/Advice_and_Troubleshooting/Data_Storage_Software/ONTAP_OS/Unable_to_connect_via_SSH_to_node_cluster_management_LIF&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;SSH connection fails after upgrade from ONTAP 9.7 to 9.8&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://kb.netapp.com/Advice_and_Troubleshooting/Data_Storage_Software/ONTAP_OS/SSH_connection_fails_after_upgrade_from_ONTAP_9.7_to_9.8" target="_blank" rel="noopener"&gt;https://kb.netapp.com/Advice_and_Troubleshooting/Data_Storage_Software/ONTAP_OS/SSH_connection_fails_after_upgrade_from_ONTAP_9.7_to_9.8&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 16 Feb 2021 23:15:04 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/quot-security-ssh-quot-configuration/m-p/164060#M37547</guid>
      <dc:creator>jcolonfzenpr</dc:creator>
      <dc:date>2021-02-16T23:15:04Z</dc:date>
    </item>
    <item>
      <title>Re: "security ssh" configuration</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/quot-security-ssh-quot-configuration/m-p/164065#M37548</link>
      <description>&lt;P&gt;Regarding the first KB, the SSH service is running, it is listed when i enter "netstat -a". And the second KB, i had removed already the problematic SHA1&amp;nbsp;Key Exchange Algorithm from my config.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Possible that i have a completely different problem, but i have modified the SSH security config. And now one week later i can't do a SSH to the controller.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When it's done after a few days automatically, so i was thinking there must be a way to restart the SSH service without rebooting the controller.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there a log where i can see problems with SSH? (systemshell or spi?)&lt;/P&gt;</description>
      <pubDate>Wed, 17 Feb 2021 07:45:55 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/quot-security-ssh-quot-configuration/m-p/164065#M37548</guid>
      <dc:creator>sraudonis</dc:creator>
      <dc:date>2021-02-17T07:45:55Z</dc:date>
    </item>
    <item>
      <title>Re: "security ssh" configuration</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/quot-security-ssh-quot-configuration/m-p/164066#M37549</link>
      <description>&lt;P&gt;Ah, i found something in the messages.log:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;sshd 65444 - - fatal: /etc/ssh/sshd_config line 102: Bad SSH2 mac spec 'hmac-sha2-256,hmac-sha2-512,hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,umac-128@openssh.com-etm,umac-128,hmac-sha1,hmac-sha1-96,hmac-sha1-etm@openssh.com,hmac-sha1-96-etm@openssh.com,hmac-md5,hmac-md5-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,umac-64-etm@openssh.com'.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This line i got when trying to login. So i will compare later with a untouched system...&lt;/P&gt;</description>
      <pubDate>Wed, 17 Feb 2021 08:01:03 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/quot-security-ssh-quot-configuration/m-p/164066#M37549</guid>
      <dc:creator>sraudonis</dc:creator>
      <dc:date>2021-02-17T08:01:03Z</dc:date>
    </item>
    <item>
      <title>Re: "security ssh" configuration</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/quot-security-ssh-quot-configuration/m-p/164067#M37550</link>
      <description>&lt;P&gt;I found the problem:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;sshd 65444 - - fatal: /etc/ssh/sshd_config line 102: Bad SSH2 mac spec 'hmac-sha2-256,hmac-sha2-512,hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,&lt;U&gt;&lt;STRONG&gt;umac-128@openssh.com-etm&lt;/STRONG&gt;&lt;/U&gt;,umac-128,hmac-sha1,hmac-sha1-96,hmac-sha1-etm@openssh.com,hmac-sha1-96-etm@openssh.com,hmac-md5,hmac-md5-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,umac-64-etm@openssh.com'.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If i remove that mac from the config i'm able to login again.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And i can reproduce that, so i open a case for that, this is a bug...&lt;/P&gt;</description>
      <pubDate>Wed, 17 Feb 2021 08:48:49 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/quot-security-ssh-quot-configuration/m-p/164067#M37550</guid>
      <dc:creator>sraudonis</dc:creator>
      <dc:date>2021-02-17T08:48:49Z</dc:date>
    </item>
    <item>
      <title>Re: "security ssh" configuration</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/quot-security-ssh-quot-configuration/m-p/164069#M37552</link>
      <description>&lt;P&gt;Similar KB:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://kb.netapp.com/Advice_and_Troubleshooting/Data_Storage_Software/ONTAP_OS/SSH_fails_to_connect_to_node_due_to_presence_of_%22hmac-ripemd160%22_and%2F%2For_%22hmac-ripemd160-etm%22_MAC_algorithms" target="_blank" rel="noopener"&gt;https://kb.netapp.com/Advice_and_Troubleshooting/Data_Storage_Software/ONTAP_OS/SSH_fails_to_connect_to_node_due_to_presence_of_%22hmac-ripemd160%22_and%2F%2For_%22hmac-ripemd160-etm%22_MAC_algorithms&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Feb 2021 13:06:08 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/quot-security-ssh-quot-configuration/m-p/164069#M37552</guid>
      <dc:creator>jcolonfzenpr</dc:creator>
      <dc:date>2021-02-17T13:06:08Z</dc:date>
    </item>
    <item>
      <title>Re: "security ssh" configuration</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/quot-security-ssh-quot-configuration/m-p/164070#M37553</link>
      <description>&lt;P&gt;No it isn't, you can try the following if you have access to the SP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Enter the following two commands:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;security ssh remove -vserver &amp;lt;cluster&amp;gt; -mac-algorithms umac-128&lt;BR /&gt;security ssh remove -vserver &amp;lt;cluster&amp;gt; -mac-algorithms umac-128-etm&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;and now add the "-etm" back again:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;security ssh add -vserver &amp;lt;cluster&amp;gt; -mac-algorithms umac-128-etm&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Test if you can do a SSH to the controller, you will see, you can't...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Remove it again:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;security ssh remove -vserver &amp;lt;cluster&amp;gt; -mac-algorithms umac-128-etm&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And add it again but before the "-etm" add the other:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;security ssh add -vserver &amp;lt;cluster&amp;gt; -mac-algorithms umac-128&lt;BR /&gt;security ssh add -vserver &amp;lt;cluster&amp;gt; -mac-algorithms umac-128-etm&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Then yo can do a SSH to the ccontroller.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Must be a bug...&lt;/P&gt;</description>
      <pubDate>Wed, 17 Feb 2021 13:08:31 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/quot-security-ssh-quot-configuration/m-p/164070#M37553</guid>
      <dc:creator>sraudonis</dc:creator>
      <dc:date>2021-02-17T13:08:31Z</dc:date>
    </item>
  </channel>
</rss>

