Upcoming Security Update: Changes to SFTP Cipher Support

As part of Sandata's commitment to maintaining the highest security standards, we will update our SFTP library settings effective February 19, 2025. Certain older technology you may currently use on your SFTP site will no longer be supported.

What This Means for You

If your SFTP site uses on of the deprecated settings, you may experience connection issues with Sandata products after the update. The following protocols will no longer be supported on February 19, 2025. 

KEX algorithms: 

  • diffie-hellman-group14-sha1
  • diffie-hellman-group-exchange-sha1
  • diffie-hellman-group1-sha1

Host Key algorithms:

  • ssh-rsa
  • ssh-dss

Ciphers:

  • aes128-cbc
  • 3des-ctr
  • 3des-cbc
  • blowfish-cbc
  • aes192-cbc
  • aes256-cbc

MACs:

  • hman-md5
  • hmac-sha1-96
  • hmac-md5-96

Supported Protocols

KEX algorithms:

  • ecdh-sha2-nistp256
  • ecdh-sha2-nistp384
  • ecdh-sha2-nistp521
  • diffie-hellman-group-exchange-sha256
  • diffie-hellman-group16-sha512
  • diffie-hellman-group18-sha512
  • diffie-hellman-group14-sha256
  • ext-info-c
  • kex-strict-c-v00@openssh.com

Host Key algorithms:

  • ecdsa-sha2-nistp256
  • ecdsa-sha2-nistp384
  • ecdsa-sha2-nistp521
  • rsa-sha2-512
  • rsa-sha2-256

Ciphers:

MACs

  • hmac-sha2-256-etm@openssh.com
  • hmac-sha2-512-etm@openssh.com
  • hmac-sha1-etm@openssh.com
  • hmac-sha2-256
  • hmac-sha2-512
  • hmac-sha1

If you need assistance, please Submit a Request via Sandata On-Demand. 

Comments

0 comments

Please sign in to leave a comment.