Network Management
Upgrading to FortiOS / Fortigate 7.2.6 - 7.2.7 or 7.0.13 - 7.0.14, Fortinet devices are no longer connecting in NCM due to supportability for SSH-ED25519 algorithm
After upgrading to FortiOS / Fortigate 7.2.6 - 7.2.7 or 7.0.13 - 7.0.14, Fortinet devices no longer connect through SSH in NCM with the message of "Server signature does not match".
First published date
Last published date
Overview
After upgrading to FortiOS / Fortigate 7.2.6 - 7.2.7 or 7.0.13 - 7.0.14, Fortinet devices no longer connect through SSH with NCM with the message "Server signature does not match".
Session Trace Logging samples: Negotiation failed: no matching host key type found. Unable to negotiate with X.X.X.X: no matching host key type found. Error: Server Signature does not match SSH Logging through PuTTY: SSH: fatal: Unable to negotiate with X.X.X.X: no matching host key type found. Their offer: rsa-sha2-512,rsa-sha2-256,ssh-rsa,ssh-dss SSH: Client protocol version 1.99; client software version WeOnlyDo.Net SSH: no match: WeOnlyDo.Net
Product section
Cause
In the FortiOS / Fortigate 7.2.6 - 7.2.7 or 7.0.13 - 7.0.14, rsa-ssh key signature algorithm were removed causing only SSH-ED25519 to be available.
NCM 2024.1 and earlier does not support the SSH-ED25519 key signature algorithm.
FortiOS ID 874292, where the RSA algorithm was removed for being obsolete.
FortiOS 7.2.6 ID874292: ssh-rsa should be disabled under the SSH server_host_key_algorithm.
Resolved issues | FortiGate / FortiOS 7.2.6 | Fortinet Document Library
Resolved issues | FortiGate / FortiOS 7.0.13 | Fortinet Document Library
Known issues | FortiGate / FortiOS 7.2.7 | Fortinet Document Library
Resolution
To resolve this problem, please upgrade to SolarWinds Platform 2024.1.1. For customers running 2024.1, if you cannot upgrade, then apply the buddy drop for SolarWinds Platform 2024.1.
For more information, please refer to SolarWinds-NCM-2024-1-0-BD-OO-29404-additional-steps.