set kex-algorithms

Last Updated : Jun 01, 2021 |

Syntax

set kex-algorithms <default | all | {kex} [{kex}...]>

Parameters

Parameter

Description

Possible values

Default value

<kex>

diffie-hellman-group14-sha1,

diffie-hellman-group-exchange-sha1,

diffie-hellman-group-exchange-sha256,

all

default

Description

Set SSH client's key exchange (kex) algorithms.

If an SCP transfer for a gateway in FIPS mode returns the following error:

server offered non-Approved DH group
You can change the key exchange list to have diffie-hellman-group14-sha1 as the first element.

Context

ssh-client-configuration

User level

admin

Examples

# set kex-algorithms diffie-hellman-group-exchange-sha1 diffie-hellman-group14-sha1
KexAlgorithms: diffie-hellman-group-exchange-sha1 diffie-hellman-group14-sha1
# set kex-algorithms default
KexAlgorithms: diffie-hellman-group14-sha1 diffie-hellman-group-exchange-sha1 diffie-hellman-group-exchange-sha256
# set kex-algorithms all
KexAlgorithms: diffie-hellman-group14-sha1 diffie-hellman-group-exchange-sha1 diffie-hellman-group-exchange-sha256