12-09-2021 02:35 PM
Do the ICX 7450/7750 series switches support high encryption (i.e. SHA256) for SSH and NTP connections?
Solved! Go to Solution.
12-09-2021 02:52 PM
Hey Joseph,
In terms of non-FIPS (normal) mode, SHA256 was added for SSH in 9000a via:
ICX(config)#ip ssh key-exchange-method dh-group14-sha256
I do not believe it is available for NTP in any release.
If you are running FIPS mode, SHA256 will be used by default for SSH. With that said, FIPS is going to lock down the box quite a bit, so I would make sure you 100% want to go down that route before enabling that mode:
https://support.ruckuswireless.com/documents/3026-fastiron-08-0-90-ga-fips-common-criteria-guide
I should note we are still recommending 8090 code stream at this time, but if you are specifically looking for SHA256 for SSH while in non-FIPS mode, you would need to run 9.x .