rsa-sha2-512 and rsa-sha2-256 server host key are not configurable in the SSH Service Profile

rsa-sha2-512 and rsa-sha2-256 server host key are not configurable in the SSH Service Profile

9520
Created On 05/27/22 23:31 PM - Last Modified 12/19/24 21:27 PM


Symptom


  • rsa-sha2-512 and rsa-sha2-256 need to be added under GUI: Device > Certificate Management > SSH Service Profile > Management Server Profile > (Add) >Hostkey 
  • There is no rsa-sha2-512 and rsa-sha2-256 under Hostkey.

Screen Shot 2022-05-23 at 12.04.00 PM.png



Environment


  • Palo Alto Firewalls or Panorama
  • PANOS 10.0.x and above
  • SSH Service Profile


Cause


  • Values 2048, 3072, and 4096 are the key length. The default key type and length is RSA 2048.


Resolution


  1. When configuring the SSH profile for management, select any key length 2048, 3072 or 4096.
  2. Select the configured Profile by going to GUI: Device > Setup > Management > SSH Management Profile Settings > select the SSH Service Profile
  3. Commit
  4. Run the following command from CLI.
> set ssh service-restart mgmt
  1. Test the changes from a client device. All the rsa based ciphers are seen advertised.
 nmap --script ssh2-enum-algos -sV -p 22 x.y.z.q //Replace x.y.z.q with firewall management IP

Screen Shot 2022-05-23 at 11.45.26 AM.png
Note:

  • When RSA server host keys are configured then all the rsa based ciphers get advertised - that includes ssh-rsa, rsa-sha2-256 & rsa-sha2-512, this is regardless of which RSA key strength is configured.
  • To Prune out the ssh-rsa server host key algorithm, set any ECDSA-based key as the server host key algorithm. 
  • When you do this all the rsa-based server host key algorithms are pruned out. And only the corresponding ecdsa-sha2-* based server host key algorithm is advertised.


Additional Information


  • Configure an SSH Service Profile.
  • Make sure to have a backup of configurations before making any changes.
  • If Firewall is in a HA  environment, make the changes on Passive Firewall first.


Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000CplrCAC&lang=en_US&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail

Choose Language