What determines what algorithms are available to OpenSSH?












1















Is the version of OpenSSH or the version of OpenSSL (or a combination of the two) that is installed on a given system what determines which Ciphers, KexAlgorithms, and MACs are available to be configured for use?



Background: We have a legacy process that is using SSH/SFTP to exchange data between an outside organization and ours. The outside organization is going to begin enforcing the use of stronger crytographic algorithms. No surprise, the instance of either OpenSSH or OpenSSL installed on our end is not up to snuff.



Trying to figure out where I would need to look to determine what minimum level I need to make this work in the short term. What version of which package would carry a given algorithm?










share|improve this question

























  • OpenSSH can be built with OpenSSL support or without. Check if your version depends on libssl or similar, which would indicate it's built with OpenSSL.

    – garethTheRed
    Jan 10 at 18:50











  • i see libcrypto, but not libssl specifically

    – Erik
    Jan 10 at 20:01






  • 1





    @Erik libcrypto is the relevant library from OpenSSL that OpenSSH links against. It just uses the cryptographic functions, not the TLS implementation.

    – Austin Hemmelgarn
    Jan 10 at 20:02






  • 1





    @Erik - That depends on how OpenSSL was built.

    – Ramhound
    Jan 11 at 12:46






  • 1





    Any specific reason to not just use the currently available latest version?

    – grawity
    Jan 11 at 12:47
















1















Is the version of OpenSSH or the version of OpenSSL (or a combination of the two) that is installed on a given system what determines which Ciphers, KexAlgorithms, and MACs are available to be configured for use?



Background: We have a legacy process that is using SSH/SFTP to exchange data between an outside organization and ours. The outside organization is going to begin enforcing the use of stronger crytographic algorithms. No surprise, the instance of either OpenSSH or OpenSSL installed on our end is not up to snuff.



Trying to figure out where I would need to look to determine what minimum level I need to make this work in the short term. What version of which package would carry a given algorithm?










share|improve this question

























  • OpenSSH can be built with OpenSSL support or without. Check if your version depends on libssl or similar, which would indicate it's built with OpenSSL.

    – garethTheRed
    Jan 10 at 18:50











  • i see libcrypto, but not libssl specifically

    – Erik
    Jan 10 at 20:01






  • 1





    @Erik libcrypto is the relevant library from OpenSSL that OpenSSH links against. It just uses the cryptographic functions, not the TLS implementation.

    – Austin Hemmelgarn
    Jan 10 at 20:02






  • 1





    @Erik - That depends on how OpenSSL was built.

    – Ramhound
    Jan 11 at 12:46






  • 1





    Any specific reason to not just use the currently available latest version?

    – grawity
    Jan 11 at 12:47














1












1








1








Is the version of OpenSSH or the version of OpenSSL (or a combination of the two) that is installed on a given system what determines which Ciphers, KexAlgorithms, and MACs are available to be configured for use?



Background: We have a legacy process that is using SSH/SFTP to exchange data between an outside organization and ours. The outside organization is going to begin enforcing the use of stronger crytographic algorithms. No surprise, the instance of either OpenSSH or OpenSSL installed on our end is not up to snuff.



Trying to figure out where I would need to look to determine what minimum level I need to make this work in the short term. What version of which package would carry a given algorithm?










share|improve this question
















Is the version of OpenSSH or the version of OpenSSL (or a combination of the two) that is installed on a given system what determines which Ciphers, KexAlgorithms, and MACs are available to be configured for use?



Background: We have a legacy process that is using SSH/SFTP to exchange data between an outside organization and ours. The outside organization is going to begin enforcing the use of stronger crytographic algorithms. No surprise, the instance of either OpenSSH or OpenSSL installed on our end is not up to snuff.



Trying to figure out where I would need to look to determine what minimum level I need to make this work in the short term. What version of which package would carry a given algorithm?







linux openssh openssl algorithm






share|improve this question















share|improve this question













share|improve this question




share|improve this question








edited Jan 11 at 12:33







Erik

















asked Jan 10 at 17:35









ErikErik

36137




36137













  • OpenSSH can be built with OpenSSL support or without. Check if your version depends on libssl or similar, which would indicate it's built with OpenSSL.

    – garethTheRed
    Jan 10 at 18:50











  • i see libcrypto, but not libssl specifically

    – Erik
    Jan 10 at 20:01






  • 1





    @Erik libcrypto is the relevant library from OpenSSL that OpenSSH links against. It just uses the cryptographic functions, not the TLS implementation.

    – Austin Hemmelgarn
    Jan 10 at 20:02






  • 1





    @Erik - That depends on how OpenSSL was built.

    – Ramhound
    Jan 11 at 12:46






  • 1





    Any specific reason to not just use the currently available latest version?

    – grawity
    Jan 11 at 12:47



















  • OpenSSH can be built with OpenSSL support or without. Check if your version depends on libssl or similar, which would indicate it's built with OpenSSL.

    – garethTheRed
    Jan 10 at 18:50











  • i see libcrypto, but not libssl specifically

    – Erik
    Jan 10 at 20:01






  • 1





    @Erik libcrypto is the relevant library from OpenSSL that OpenSSH links against. It just uses the cryptographic functions, not the TLS implementation.

    – Austin Hemmelgarn
    Jan 10 at 20:02






  • 1





    @Erik - That depends on how OpenSSL was built.

    – Ramhound
    Jan 11 at 12:46






  • 1





    Any specific reason to not just use the currently available latest version?

    – grawity
    Jan 11 at 12:47

















OpenSSH can be built with OpenSSL support or without. Check if your version depends on libssl or similar, which would indicate it's built with OpenSSL.

– garethTheRed
Jan 10 at 18:50





OpenSSH can be built with OpenSSL support or without. Check if your version depends on libssl or similar, which would indicate it's built with OpenSSL.

– garethTheRed
Jan 10 at 18:50













i see libcrypto, but not libssl specifically

– Erik
Jan 10 at 20:01





i see libcrypto, but not libssl specifically

– Erik
Jan 10 at 20:01




1




1





@Erik libcrypto is the relevant library from OpenSSL that OpenSSH links against. It just uses the cryptographic functions, not the TLS implementation.

– Austin Hemmelgarn
Jan 10 at 20:02





@Erik libcrypto is the relevant library from OpenSSL that OpenSSH links against. It just uses the cryptographic functions, not the TLS implementation.

– Austin Hemmelgarn
Jan 10 at 20:02




1




1





@Erik - That depends on how OpenSSL was built.

– Ramhound
Jan 11 at 12:46





@Erik - That depends on how OpenSSL was built.

– Ramhound
Jan 11 at 12:46




1




1





Any specific reason to not just use the currently available latest version?

– grawity
Jan 11 at 12:47





Any specific reason to not just use the currently available latest version?

– grawity
Jan 11 at 12:47










0






active

oldest

votes











Your Answer








StackExchange.ready(function() {
var channelOptions = {
tags: "".split(" "),
id: "3"
};
initTagRenderer("".split(" "), "".split(" "), channelOptions);

StackExchange.using("externalEditor", function() {
// Have to fire editor after snippets, if snippets enabled
if (StackExchange.settings.snippets.snippetsEnabled) {
StackExchange.using("snippets", function() {
createEditor();
});
}
else {
createEditor();
}
});

function createEditor() {
StackExchange.prepareEditor({
heartbeatType: 'answer',
autoActivateHeartbeat: false,
convertImagesToLinks: true,
noModals: true,
showLowRepImageUploadWarning: true,
reputationToPostImages: 10,
bindNavPrevention: true,
postfix: "",
imageUploader: {
brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
allowUrls: true
},
onDemand: true,
discardSelector: ".discard-answer"
,immediatelyShowMarkdownHelp:true
});


}
});














draft saved

draft discarded


















StackExchange.ready(
function () {
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fsuperuser.com%2fquestions%2f1392863%2fwhat-determines-what-algorithms-are-available-to-openssh%23new-answer', 'question_page');
}
);

Post as a guest















Required, but never shown

























0






active

oldest

votes








0






active

oldest

votes









active

oldest

votes






active

oldest

votes
















draft saved

draft discarded




















































Thanks for contributing an answer to Super User!


  • Please be sure to answer the question. Provide details and share your research!

But avoid



  • Asking for help, clarification, or responding to other answers.

  • Making statements based on opinion; back them up with references or personal experience.


To learn more, see our tips on writing great answers.




draft saved


draft discarded














StackExchange.ready(
function () {
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fsuperuser.com%2fquestions%2f1392863%2fwhat-determines-what-algorithms-are-available-to-openssh%23new-answer', 'question_page');
}
);

Post as a guest















Required, but never shown





















































Required, but never shown














Required, but never shown












Required, but never shown







Required, but never shown

































Required, but never shown














Required, but never shown












Required, but never shown







Required, but never shown







Popular posts from this blog

Сан-Квентин

8-я гвардейская общевойсковая армия

Алькесар