Validate SSH hardening to address the vulnerabilities

Joseph S. Testa II jtesta at positronsecurity.com
Wed May 26 04:53:16 AEST 2021


On Tue, 2021-05-25 at 18:04 +0530, Kaushal Shriyan wrote:
> Is there a way to validate if the above Key exchange, Cipher and MAC
> algorithms address the vulnerabilities?

For a command-line tool, see ssh-audit: 
https://github.com/jtesta/ssh-audit

For a web front-end that gives prettier results (and references): 
https://www.ssh-audit.com/

   - Joe


-- 
Joseph S. Testa II
Founder & Principal Security Consultant
Positron Security



More information about the openssh-unix-dev mailing list