Enabling or Disabling an Insecure Algorithm
Scenarios
You can disable an insecure algorithm in your bastion host system to enhance security. If an insecure algorithm is disabled, the bastion host cannot use it (as shown in Table 1).
By default, insecure algorithms are disabled on a bastion host. However, you may need to enable insecure algorithms in some special scenarios, for example:
- Interconnection with third-party systems: If your bastion host needs to interconnect with third-party systems or old devices that use insecure algorithms, insecure algorithms must be enabled to ensure normal service transfer.
- Compatibility with old devices: If you need to manage systems or devices that use insecure algorithms through a bastion host, insecure algorithms must be enabled to ensure backward compatibility and continuity of O&M management.
- Smooth transition: During the transition phase of cryptographic algorithm upgrade and reconstruction, some old systems may not support secure algorithms. In this case, insecure algorithms must be temporarily enabled to ensure smooth service migration.
Precautions
Insecure algorithms have security risks. You are advised to disable these algorithms in a timely manner after they are no longer used and avoid entering sensitive information while they remain enabled.
Prerequisites
The role you belong to has the management permission for the System module. For details about how to check the permissions of each role, see Role.
Enabling or Disabling an Insecure Algorithm
- Log in to your bastion host system.
- In the navigation pane on the left, choose System > System Config > Security.
- On the right of the Algorithm Config area, click Edit. Figure 1 Configuring algorithms
- After enabling or disabling an insecure algorithm, click OK. Figure 2 Enabling an insecure algorithm
Insecure Algorithms
Table 1 lists the insecure algorithms that you may need to enable.
| Kex | Hostkey | Cipher | MAC |
|---|---|---|---|
|
|
|
|
What is your overall rating for this page?
Thank you very much for your feedback. We will continue working to improve the documentation.See the reply and handling status in My Cloud VOC.
For any further questions, feel free to contact us through the chatbot.
Chatbot