跳转到主内容

如何在ONTAP中禁用较弱的服务器主机密钥算法"ssh-dss""ssh-rsa"

Views:
40
Visibility:
Public
Votes:
0
Category:
ontap-9
Specialty:
core<a>FIPS</a><a>SSH</a><a>服务器主机密钥</a>
Last Updated:

状态信息

适用场景

  • ONTAP 9
  • 网络安全

问题描述

漏洞扫描程序报告SSH服务器公共密钥太小:

2 port 22/tcp SSH Server Public Key Too Small
QID: 38738 Category: General remote services CVE ID: Vendor Reference: Bugtraq ID: Service Modified: 01/03/2019 User Modified: Edited: No PCI Vuln: Yes
THREAT: The SSH protocol (Secure Shell) is a method for secure remote login from one computer to another. The SSH Server is using a small Public Key. Best practices require that RSA digital signatures be 2048 or more bits long to provide adequate security. Key lengths of 1024 are acceptable through 2013, but since 2011 they are considered deprecated. For more information, please refer to NIST Special Publication 800-131A (http://nvlpubs.nist.gov/nistpubs/Spe...800-131Ar1.pdf (http://nvlpubs.nist.gov/nistpubs/Spe...800-131Ar1.pdf)). Only server keys that are not part of a certificate are reported in this QID. OpenSSH certificates using short keys are reported in QID 38733. X.509
Scan Results page 8 certificates using short keys are reported in QID 38171.
IMPACT: A man-in-the-middle attacker can exploit this vulnerability to record the communication to decrypt the session key and even the messages.
SOLUTION: DSA keys and RSA keys shorter than 2048 bits are considered vulnerable. It is recommended to install a RSA public key length of at least 2048 bits or greater, or to switch to ECDSA or EdDSA.
COMPLIANCE: Not Applicable
EXPLOITABILITY: There is no exploitability information for this vulnerability.
ASSOCIATED MALWARE: There is no malware information for this vulnerability.
RESULTS: Algorithm Length ssh-dss 1024 bits

 

Sign in to view the entire content of this KB article.

New to NetApp?

Learn more about our award-winning Support

NetApp provides no representations or warranties regarding the accuracy or reliability or serviceability of any information or recommendations provided in this publication or with respect to any results that may be obtained by the use of the information or observance of any recommendations provided herein. The information in this document is distributed AS IS and the use of this information or the implementation of any recommendations or techniques herein is a customer's responsibility and depends on the customer's ability to evaluate and integrate them into the customer's operational environment. This document and the information contained herein may be used solely in connection with the NetApp products discussed in this document.