Package: client

The client does not support chacha20 as I get this error when I try to
connect to the X2Go server. I did harden my SSH configuration as guided by
Mozzila
https://infosec.mozilla.org/guidelines/openssh

When I use defaults it works fine. It seems that the library used by X2Go
is missing some newer methods.

Config:
server ssh config:
KexAlgorithms curve25519-sha...@libssh.org
,ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group-exchange-sha256
Ciphers chacha20-poly1...@openssh.com,aes256-...@openssh.com,
aes128-...@openssh.com,aes256-ctr,aes192-ctr,aes128-ctr
MACs hmac-sha2-512-...@openssh.com,hmac-sha2-256-...@openssh.com,
umac-128-...@openssh.com,hmac-sha2-512,hmac-sha2-256,umac-...@openssh.com

Client sshd config:
Client using default sshd config

or

HashKnownHosts yes
HostKeyAlgorithms ssh-ed25519-cert-...@openssh.com,
ssh-rsa-cert-...@openssh.com,ssh-ed25519,ssh-rsa,
ecdsa-sha2-nistp521-cert-...@openssh.com,
ecdsa-sha2-nistp384-cert-...@openssh.com,
ecdsa-sha2-nistp256-cert-...@openssh.com
,ecdsa-sha2-nistp521,ecdsa-sha2-nistp384,ecdsa-sha2-nistp256
KexAlgorithms curve25519-sha...@libssh.org
,ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group-exchange-sha256
MACs hmac-sha2-512-...@openssh.com,hmac-sha2-256-...@openssh.com,
umac-128-...@openssh.com,hmac-sha2-512,hmac-sha2-256,umac-...@openssh.com
Ciphers chacha20-poly1...@openssh.com,aes256-...@openssh.com,
aes128-...@openssh.com,aes256-ctr,aes192-ctr,aes128-ctr

Error:
"kex error : no match for method mac algo client->server: server [
hmac-sha2-512-...@openssh.com,hmac-sha2-256-...@openssh.com,
umac-128-...@openssh.com,hmac-sha2-512,hmac-sha2-256,umac-...@openssh.com],
client [hmac-sha1]"

or sometimes

"crypt_set_algorithms2: no crypto algorithm function found for
chacha20-poly1...@openssh.com"

Let me know if I can provide more information.

Regards,
*Danie de Jager*
_______________________________________________
x2go-dev mailing list
x2go-dev@lists.x2go.org
https://lists.x2go.org/listinfo/x2go-dev

Reply via email to