Network Management

Supported algorithms and ciphers for SSH communications by NPM, NCM, and SolarWinds Platform

List of the supported algorithms and ciphers for NPM, NCM, and SolarWinds Platform

First published date

11/13/2020 10:37 PM

Last published date

4/1/2026 6:01 PM

Overview

SolarWinds Platform SSH communication uses algorithms and ciphers for device security. These are the list of supported algorithms and ciphers for NPM, NCM, and SolarWinds Platform.

Product section

Network Configuration Manager

Cause

Example errors from Session Traces showing algorithm negotiation or authentication issues between NCM (client) and device (server):

Connection Error : System.Exception: Could not negotiate key exchange algorithm
Connection Error : WeOnlyDo.Exceptions.SSH.AuthorizationException: Authentication with the server failed.

The Session Traces will show what algorithms are supported by NCM (client), as in the example below:

EncryptionList: aes128-ctr,aes128-cbc,3des-cbc,blowfish-cbc,aes192-ctr,aes192-cbc,aes256-ctr,aes256-cbc,chacha20-poly1305@openssh.com,rijndael-cbc@lysator.liu.se
[..]
KeyExchangeList: ecdh-sha2-nistp256,ecdh-sha2-nistp384,diffie-hellman-group-exchange-sha256,diffie-hellman-group-exchange-sha1,diffie-hellman-group1-sha1,diffie-hellman-group14-sha1
[..]
HMacList: hmac-sha2-256,hmac-sha2-512,hmac-sha1,hmac-sha1-96

Resolution

Versions:

Notes

  • The aes256-ctr encryption algorithm should not be used with hmac-sha1-96. Use hmac-sha1 instead.
  • If a device managed by NCM or Hybrid Cloud Availability requires a different set of ciphers/algorithms that are available in the newer release of the product, you will need to upgrade your SolarWinds Platform. Please see the SolarWinds Platform Products Installation and Upgrade Guide for details.

Versions 2026.2 and above

Key Exchange algorithms

  • mlkem768x25519-sha256
  • curve25519-sha256
  • curve25519-sha256@libssh.org
  • ecdh-sha2-nistp521
  • ecdh-sha2-nistp384
  • ecdh-sha2-nistp256
  • diffie-hellman-group18-sha512
  • diffie-hellman-group16-sha512
  • diffie-hellman-group14-sha256
  • diffie-hellman-group-exchange-sha256
  • diffie-hellman-group14-sha1
  • diffie-hellman-group-exchange-sha1
  • diffie-hellman-group1-sha1

Server Host algorithms

  • rsa-sha2-512
  • rsa-sha2-256
  • ssh-ed25519
  • ecdsa-sha2-nistp256
  • ecdsa-sha2-nistp384
  • ssh-rsa
  • ssh-dss

Encryption algorithms

  • aes128-ctr
  • aes128-cbc
  • aes128-gcm
  • 3des-cbc
  • aes192-ctr
  • aes192-cbc
  • >aes192-gcm
  • aes256-ctr
  • aes256-cbc
  • aes256-gcm
  • blowfish-cbc (for no FIPS)
  • chacha20-poly130
  • rijndael-cbc

MAC algorithms

  • hmac-sha2-256-etm@openssh.com
  • hmac-sha2-256
  • hmac-sha2-512-etm@openssh.com
  • hmac-sha1-etm@openssh.com
  • hmac-sha2-512
  • hmac-sha1
  • hmac-sha1-96
  • mac-md5

Versions 2025.2 through 2026.1

Key Exchange algorithms

  • diffie-hellman-group18-sha512
  • ecdh-sha2-nistp384
  • ecdh-sha2-nistp256
  • diffie-hellman-group14-sha256
  • diffie-hellman-group-exchange-sha256
  • diffie-hellman-group14-sha1
  • diffie-hellman-group-exchange-sha1
  • diffie-hellman-group1-sha1

Server Host algorithms

  • rsa-sha2-512
  • rsa-sha2-256
  • ssh-ed25519
  • ecdsa-sha2-nistp256
  • ecdsa-sha2-nistp384
  • ssh-rsa
  • ssh-dss

Encryption algorithms

  • aes128-ctr
  • aes128-cbc
  • aes128-gcm
  • 3des-cbc
  • aes192-ctr
  • aes192-cbc
  • aes192-gcm
  • aes256-ctr
  • aes256-cbc
  • aes256-gcm
  • blowfish-cbc (for no FIPS)
  • chacha20-poly130
  • rijndael-cbc

MAC algorithms

  • hmac-sha2-256-etm@openssh.com 
  • hmac-sha2-256
  • hmac-sha2-512-etm@openssh.com
  • hmac-sha1-etm@openssh.com
  • hmac-sha2-512
  • hmac-sha1
  • hmac-sha1-96
  • hmac-md5

Versions 2024.1.1 through 2025.1

    Key Exchange algorithms

    • diffie-hellman-group14-sha256
    • diffie-hellman-group-exchange-sha256
    • diffie-hellman-group-exchange-sha1
    • diffie-hellman-group1-sha1
    • diffie-hellman-group14-sha1
    • ecdh-sha2-nistp256
    • ecdh-sha2-nistp384
    • ext-info-c

    Server Host algorithms

    • rsa-sha2-512
    • rsa-sha2-256
    • ssh-ed25519
    • ecdsa-sha2-nistp256
    • ecdsa-sha2-nistp384
    • ssh-rsa,ssh-dss

    Encryption algorithms

    • aes128-ctr
    • aes128-cbc
    • aes128-gcm
    • 3des-cbc
    • aes192-ctr
    • aes192-cbc
    • aes192-gcm
    • aes256-ctr
    • aes256-cbc
    • aes256-gcm
    • blowfish-cbc (for no FIPS)
    • chacha20-poly130
    • rijndael-cbc

    MAC algorithms

    • hmac-sha2-256-etm
    • hmac-sha2-256
    • hmac-sha2-512-etm
    • hmac-sha1-etm
    • hmac-sha2-512
    • hmac-sha1
    • hmac-sha1-96

    Versions 2023.1, 2023.2, 2023.3, 2023.4, and 2024.1

      Key Exchange algorithms

      • diffie-hellman-group14-sha256
      • diffie-hellman-group-exchange-sha256
      • diffie-hellman-group-exchange-sha1
      • diffie-hellman-group1-sha1
      • diffie-hellman-group14-sha1
      • ecdh-sha2-nistp256
      • ecdh-sha2-nistp384
      • ext-info-c

      Server Host algorithms

      • rsa-sha2-512
      • rsa-sha2-256
      • ssh-rsa
      • ssh-dss

      Encryption algorithms

      • aes128-ctr
      • aes128-cbc
      • 3des-cbc
      • aes192-ctr
      • aes192-cbc
      • aes256-ctr
      • aes256-cbc
      • blowfish-cbc (for no FIPS)
      • chacha20-poly130
      • rijndael-cbc

      MAC algorithms

      • hmac-sha2-256
      • hmac-sha2-512
      • hmac-sha1
      • hmac-sha1-96
      • hmac-md5
      • none

      Versions 2022.2, 2022.3, and 2022.4

        Key Exchange algorithms

        • diffie-hellman-group14-sha256
        • diffie-hellman-group-exchange-sha256
        • diffie-hellman-group-exchange-sha1
        • diffie-hellman-group1-sha1
        • diffie-hellman-group14-sha1
        • ecdh-sha2-nistp256
        • ecdh-sha2-nistp384
        • ext-info-c

        Server Host algorithms

        • rsa-sha2-512
        • rsa-sha2-256
        • ssh-rsa
        • ssh-dss

        Encryption algorithms

        • aes128-ctr
        • aes128-cbc
        • 3des-cbc
        • aes192-ctr
        • aes192-cbc
        • aes256-ctr
        • aes256-cbc
        • blowfish-cbc (for no FIPS)
        • chacha20-poly130
        • rijndael-cbc

        MAC algorithms

        • hmac-sha2-256
        • hmac-sha2-512
        • hmac-sha1
        • hmac-sha1-96
        • hmac-md5
        • none

        Version 2020.2.6

        Key Exchange algorithms

        • diffie-hellman-group14-sha256
        • diffie-hellman-group-exchange-sha256
        • diffie-hellman-group-exchange-sha1
        • diffie-hellman-group1-sha1
        • diffie-hellman-group14-sha1
        • ecdh-sha2-nistp256
        • ecdh-sha2-nistp384
        • ext-info-c

        Server Host algorithms

        • rsa-sha2-512
        • rsa-sha2-256
        • ssh-rsa,ssh-dss

        Encryption algorithms

        • aes128-ctr
        • aes128-cbc
        • 3des-cbc,blowfish-cbc
        • aes192-ctr,aes192-cbc
        • aes256-ctr,aes256-cbc
        • chacha20-poly1305
        • rijndael-cbc

        MAC algorithms

        • hmac-sha2-256
        • hmac-sha2-512
        • hmac-sha1
        • hmac-sha1-96