Restriction for SSH Algorithms for Common Criteria Certification
-
Starting from Cisco IOS XE Release 17.10, the following Key Exchange and MAC algorithms are removed from the default list:
Key Exchange algorithm:
-
diffie-hellman-group14-sha1
MAC algorithms:
-
hmac-sha1
-
hmac-sha2-256
-
hmac-sha2-512
Note
You can use the ip ssh server algorithm kex command to configure the Key Exchange algorithm and the ip ssh server algorithm mac command to configure the MAC algorithms.
-