Tools

Disabling SSH-RSA when flagged as a vulnerability

This article explains the security concerns when SSH-RSA is flagged as a weak key algorithm in Serv-U.

First published date

7/23/2024 12:45 AM

Last published date

4/15/2025 9:19 PM

Overview

Serv-U supports different SH host key types, including DSA, RSA, and ECDSA. These keys can be generated directly from the Serv-U Management Console.

RSA keys support different encryption algorithms, such as ssh-rsa, rsa-sha2-256, and rsa-sha2-512. Some vulnerability scans may flag ssh-rsa as a weak key algorithm causing security concerns.

 

Product section

Serv-U Managed File Transfer & Serv-U FTP Server

Resolution

Serv-U 15.5.1 is now available, please consider upgrading your environment.

In 15.5.1, the SSH-RSA key algorithm was deprecated. It is disabled by default for SSH host key algorithms and for user public key algorithms. There is a new section in Serv-U encryption settings to enable SSH-RSA when needed.

Serv-U 15.5.1 release notes