![Scannex ip.buffer Скачать руководство пользователя страница 135](http://html1.mh-extra.com/html/scannex/ip-buffer/ip-buffer_manual_1206776135.webp)
Scannex ip.buffer User Manual
© UK 2007-2021 Scannex Electronics Ltd. All rights reserved worldwide.
1 9 . S F T P C ry p to g ra p h ic E le m e n ts
The ip.buffer includes the following SSH/SFTP cryptographic components:
•
Key-Exchange (KEX) Algorithms
◦
diffie-hellman-group14-sha256
(v2.97+)
◦
diffie-hellman-group14-sha1
(v2.97+)
◦
diffie-hellman-group1-sha1
•
Key Certificate
◦
ssh-rsa
◦
ssh-dss
•
Ciphers
◦
aes256-ctr
(v2.97+)
◦
aes128-ctr
(v2.97+)
◦
aes256-cbc
◦
aes128-cbc
◦
3des-cbc
•
Secure Hash (HMAC) Algorithms
◦
hmac-sha2-256
(v2.97+)
◦
hmac-sha1
It is the SSH/SFTP server that dictates which cryptographic elements are used.
Items in red are not recommended; items in green are recommended (and used by
OpenSSH 7+ default configurations).
The SFTP client does not normally require any configuration at all on the
ip.buffer.
Only if the server is set to require 'publickey' authentication will you need to
create or install a PKI certificate (see section 14.3 - Server Certificate) - the
appropriate elements of the ip.buffer's certificate are used in the SSH/SFTP
authentication phase.
Page 131
Scannex ip.buffer User Manual
© UK 2007-2021 Scannex Electronics Ltd. All rights reserved worldwide.
1 9 . S F T P C ry p to g ra p h ic E le m e n ts
The ip.buffer includes the following SSH/SFTP cryptographic components:
•
Key-Exchange (KEX) Algorithms
◦
diffie-hellman-group14-sha256
(v2.97+)
◦
diffie-hellman-group14-sha1
(v2.97+)
◦
diffie-hellman-group1-sha1
•
Key Certificate
◦
ssh-rsa
◦
ssh-dss
•
Ciphers
◦
aes256-ctr
(v2.97+)
◦
aes128-ctr
(v2.97+)
◦
aes256-cbc
◦
aes128-cbc
◦
3des-cbc
•
Secure Hash (HMAC) Algorithms
◦
hmac-sha2-256
(v2.97+)
◦
hmac-sha1
It is the SSH/SFTP server that dictates which cryptographic elements are used.
Items in red are not recommended; items in green are recommended (and used by
OpenSSH 7+ default configurations).
The SFTP client does not normally require any configuration at all on the
ip.buffer.
Only if the server is set to require 'publickey' authentication will you need to
create or install a PKI certificate (see section 14.3 - Server Certificate) - the
appropriate elements of the ip.buffer's certificate are used in the SSH/SFTP
authentication phase.
Page 131