Red Hat Bugzilla – Bug 1375179
[RFE] RC4 and CBC ciphers shipped with openssh and openssh-server should be removed
Last modified: 2017-08-01 14:42:47 EDT
Basically the same request is in the bug #1373836 (for RHEL6.9 now). We are aware of this issue and we plan to proceed with removing insecure algorithms in future releases.
While we're at it - can we also remove the arcfour ciphers? My security scanner (Greenbone) reports: > Vulnerability Insight > The ‘arcfour‘ cipher is the Arcfour stream cipher with 128-bit keys. The Arcfour cipher is believed to be > compatible with the RC4 cipher {[}SCHNEIER{]}. Arcfour (and RC4) has problems with weak keys, and > should not be used anymore. Currently this is not yet reflected on the customer portal: https://access.redhat.com/solutions/420283 But I don't know where I would let them know... So I came here ;)
Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory, and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://access.redhat.com/errata/RHSA-2017:2029