Network Management
Supported algorithms and ciphers for SSH communications by NPM, NCM, and SolarWinds Platform
List of the supported algorithms and ciphers for NPM, NCM, and SolarWinds Platform
First published date
Last published date
Overview
SolarWinds Platform SSH communication uses algorithms and ciphers for device security. These are the list of supported algorithms and ciphers for NPM, NCM, and SolarWinds Platform.
Product section
Cause
Example errors from Session Traces showing algorithm negotiation or authentication issues between NCM (client) and device (server):
Connection Error : System.Exception: Could not negotiate key exchange algorithm
Connection Error : WeOnlyDo.Exceptions.SSH.AuthorizationException: Authentication with the server failed.
The Session Traces will show what algorithms are supported by NCM (client), as in the example below:
EncryptionList: aes128-ctr,aes128-cbc,3des-cbc,blowfish-cbc,aes192-ctr,aes192-cbc,aes256-ctr,aes256-cbc,chacha20-poly1305@openssh.com,rijndael-cbc@lysator.liu.se [..] KeyExchangeList: ecdh-sha2-nistp256,ecdh-sha2-nistp384,diffie-hellman-group-exchange-sha256,diffie-hellman-group-exchange-sha1,diffie-hellman-group1-sha1,diffie-hellman-group14-sha1 [..] HMacList: hmac-sha2-256,hmac-sha2-512,hmac-sha1,hmac-sha1-96
Resolution
Versions:
- 2026.2 and above
- 2025.2 through 2026.1
- 2024.1.1 through 2025.1
- 2023.1, 2023.2, 2023.3, 2023.4, and 2024.1
- 2022.2, 2022.3, and 2022.4
- 2020.2.6
Notes
- The aes256-ctr encryption algorithm should not be used with hmac-sha1-96. Use hmac-sha1 instead.
- If a device managed by NCM or Hybrid Cloud Availability requires a different set of ciphers/algorithms that are available in the newer release of the product, you will need to upgrade your SolarWinds Platform. Please see the SolarWinds Platform Products Installation and Upgrade Guide for details.
Versions 2026.2 and above
Key Exchange algorithms
-
mlkem768x25519-sha256
- curve25519-sha256
- curve25519-sha256@libssh.org
- ecdh-sha2-nistp521
- ecdh-sha2-nistp384
- ecdh-sha2-nistp256
- diffie-hellman-group18-sha512
- diffie-hellman-group16-sha512
- diffie-hellman-group14-sha256
- diffie-hellman-group-exchange-sha256
- diffie-hellman-group14-sha1
- diffie-hellman-group-exchange-sha1
- diffie-hellman-group1-sha1
Server Host algorithms
- rsa-sha2-512
- rsa-sha2-256
- ssh-ed25519
- ecdsa-sha2-nistp256
- ecdsa-sha2-nistp384
- ssh-rsa
- ssh-dss
Encryption algorithms
- aes128-ctr
- aes128-cbc
- aes128-gcm
- 3des-cbc
- aes192-ctr
- aes192-cbc
- >aes192-gcm
- aes256-ctr
- aes256-cbc
- aes256-gcm
- blowfish-cbc (for no FIPS)
- chacha20-poly130
- rijndael-cbc
MAC algorithms
- hmac-sha2-256-etm@openssh.com
- hmac-sha2-256
- hmac-sha2-512-etm@openssh.com
- hmac-sha1-etm@openssh.com
- hmac-sha2-512
- hmac-sha1
- hmac-sha1-96
- mac-md5
Versions 2025.2 through 2026.1
Key Exchange algorithms
- diffie-hellman-group18-sha512
- ecdh-sha2-nistp384
- ecdh-sha2-nistp256
- diffie-hellman-group14-sha256
- diffie-hellman-group-exchange-sha256
- diffie-hellman-group14-sha1
- diffie-hellman-group-exchange-sha1
- diffie-hellman-group1-sha1
Server Host algorithms
- rsa-sha2-512
- rsa-sha2-256
- ssh-ed25519
- ecdsa-sha2-nistp256
- ecdsa-sha2-nistp384
- ssh-rsa
- ssh-dss
Encryption algorithms
- aes128-ctr
- aes128-cbc
- aes128-gcm
- 3des-cbc
- aes192-ctr
- aes192-cbc
- aes192-gcm
- aes256-ctr
- aes256-cbc
- aes256-gcm
- blowfish-cbc (for no FIPS)
- chacha20-poly130
- rijndael-cbc
MAC algorithms
- hmac-sha2-256-etm@openssh.com
- hmac-sha2-256
- hmac-sha2-512-etm@openssh.com
- hmac-sha1-etm@openssh.com
- hmac-sha2-512
- hmac-sha1
- hmac-sha1-96
- hmac-md5
Versions 2024.1.1 through 2025.1
Key Exchange algorithms
- diffie-hellman-group14-sha256
- diffie-hellman-group-exchange-sha256
- diffie-hellman-group-exchange-sha1
- diffie-hellman-group1-sha1
- diffie-hellman-group14-sha1
- ecdh-sha2-nistp256
- ecdh-sha2-nistp384
- ext-info-c
Server Host algorithms
- rsa-sha2-512
- rsa-sha2-256
- ssh-ed25519
- ecdsa-sha2-nistp256
- ecdsa-sha2-nistp384
- ssh-rsa,ssh-dss
Encryption algorithms
- aes128-ctr
- aes128-cbc
- aes128-gcm
- 3des-cbc
- aes192-ctr
- aes192-cbc
- aes192-gcm
- aes256-ctr
- aes256-cbc
- aes256-gcm
- blowfish-cbc (for no FIPS)
- chacha20-poly130
- rijndael-cbc
MAC algorithms
- hmac-sha2-256-etm
- hmac-sha2-256
- hmac-sha2-512-etm
- hmac-sha1-etm
- hmac-sha2-512
- hmac-sha1
- hmac-sha1-96
Versions 2023.1, 2023.2, 2023.3, 2023.4, and 2024.1
Key Exchange algorithms
- diffie-hellman-group14-sha256
- diffie-hellman-group-exchange-sha256
- diffie-hellman-group-exchange-sha1
- diffie-hellman-group1-sha1
- diffie-hellman-group14-sha1
- ecdh-sha2-nistp256
- ecdh-sha2-nistp384
- ext-info-c
Server Host algorithms
- rsa-sha2-512
- rsa-sha2-256
- ssh-rsa
- ssh-dss
Encryption algorithms
- aes128-ctr
- aes128-cbc
- 3des-cbc
- aes192-ctr
- aes192-cbc
- aes256-ctr
- aes256-cbc
- blowfish-cbc (for no FIPS)
- chacha20-poly130
- rijndael-cbc
MAC algorithms
- hmac-sha2-256
- hmac-sha2-512
- hmac-sha1
- hmac-sha1-96
- hmac-md5
- none
Versions 2022.2, 2022.3, and 2022.4
Key Exchange algorithms
- diffie-hellman-group14-sha256
- diffie-hellman-group-exchange-sha256
- diffie-hellman-group-exchange-sha1
- diffie-hellman-group1-sha1
- diffie-hellman-group14-sha1
- ecdh-sha2-nistp256
- ecdh-sha2-nistp384
- ext-info-c
Server Host algorithms
- rsa-sha2-512
- rsa-sha2-256
- ssh-rsa
- ssh-dss
Encryption algorithms
- aes128-ctr
- aes128-cbc
- 3des-cbc
- aes192-ctr
- aes192-cbc
- aes256-ctr
- aes256-cbc
- blowfish-cbc (for no FIPS)
- chacha20-poly130
- rijndael-cbc
MAC algorithms
- hmac-sha2-256
- hmac-sha2-512
- hmac-sha1
- hmac-sha1-96
- hmac-md5
- none
Version 2020.2.6
Key Exchange algorithms
- diffie-hellman-group14-sha256
- diffie-hellman-group-exchange-sha256
- diffie-hellman-group-exchange-sha1
- diffie-hellman-group1-sha1
- diffie-hellman-group14-sha1
- ecdh-sha2-nistp256
- ecdh-sha2-nistp384
- ext-info-c
Server Host algorithms
- rsa-sha2-512
- rsa-sha2-256
- ssh-rsa,ssh-dss
Encryption algorithms
- aes128-ctr
- aes128-cbc
- 3des-cbc,blowfish-cbc
- aes192-ctr,aes192-cbc
- aes256-ctr,aes256-cbc
- chacha20-poly1305
- rijndael-cbc
MAC algorithms
- hmac-sha2-256
- hmac-sha2-512
- hmac-sha1
- hmac-sha1-96