Tools
Why SSH-RSA is deprecated in Serv-U 15.5.1
The SSH-RSA key algorithm was deprecated in Serv-U 15.5.1. It is now disabled by default for SSH host key algorithms and for user public key algorithms.
First published date
Last published date
Overview
SSH-RSA deprecated in Serv U
Serv-U supports different SSH Key Types; DSA, RSA, and ECDSA. These keys can be generated directly within the Serv-U Management Console.
RSA keys support different encryption algorithms, such as SSH-RSA, RSA-SHA2-256, and RSA-SHA2-512.
The SSH-RSA key algorithm is deprecated in Serv-U 15.5.1 and above. Serv-U 15.5.1 Release Notes
Why?
The reason behind the decision to deprecate SSH-RSA algorithm in Serv-U was informed by concerns in maintaining the application's security robustness.
This change will affect users who rely on SSH-RSA for secure connections to Serv-U whose SHA-1 hash algorithm contains a vulnerability that makes SSH-RSA insecure for cryptographic purposes.
For more information, please see https://www.nist.gov/news-events/news/2022/12/nist-retires-sha-1-cryptographic-algorithm
Looking ahead
While SSH-RSA is now disabled by default for SSH host key algorithms and for user public key algorithms, it can be re-enabled at Limits & Settings > Encryption > SSH Key Algorithms, if more time is required to switch older clients to secure alternatives.
Doing so however, weakens the overall Serv-U security posture and is not recommended.
Product section
Resolution
- Consider using more secure alternatives, like ECDSA.
- If you have clients that utilize a Key Types currently not supported in Serv-U, please submit a Feature Request at https://thwack.solarwinds.com/products/serv-u-ftp-mft/i/feature-requests for consideration.