Vuln Scanner reports : SSH2 Algorithm Negotiation Enumeration

From: Saxon, Stuart (Stuart.Saxon@centrica.co.uk)
Date: Thu Oct 12 2006 - 06:18:39 EDT


Hi gurus,

Does anyone know what this means.

I have been tasked with making a secure build of Solaris 9.9-05.

To test the security team have ran their vuln scanner against my test
host.

Great thing is that they are happy and have rated my build 100%
compliant.

However, the only vuln reported is

"SSH2 Algorithm Negotiation Enumeration"

And I want ZERO.

As said above I am running Solaris 9.9-05 and using Sun's SSH

I've googled around but nothing that I can read and understand.
I've had a trawl through the ssh configs and can't seem anything to
switch on/off.

Help if you can - and thanks in advance

Stuart Saxon
Datacenter Engineering Standards Team
Centrica
Mobile: 07789 571811

_____________________________________________________________________
The information contained in or attached to this email is intended only for
the use of the individual or entity to which it is addressed. If you are not
the intended recipient, or a person responsible for delivering it to the
intended recipient, you are not authorised to and must not disclose, copy,
distribute, or retain this message or any part of it. It may contain
information which is confidential and/or covered by legal professional or
other privilege (or other rules or laws with similar effect in jurisdictions
outside England and Wales).
The views expressed in this email are not necessarily the views of Centrica
plc, and the company, its directors, officers or employees make no
representation or accept any liability for its accuracy or completeness unless
expressly stated to the contrary.
_______________________________________________
sunmanagers mailing list
sunmanagers@sunmanagers.org
http://www.sunmanagers.org/mailman/listinfo/sunmanagers



This archive was generated by hypermail 2.1.7 : Wed Apr 09 2008 - 23:40:59 EDT