Skip to Main Content
Integration


This is an IBM Automation portal for Integration products. To view all of your ideas submitted to IBM, create and manage groups of Ideas, or create an idea explicitly set to be either visible by all (public) or visible only to you and IBM (private), use the IBM Unified Ideas Portal (https://ideas.ibm.com).


Shape the future of IBM!

We invite you to shape the future of IBM, including product roadmaps, by submitting ideas that matter to you the most. Here's how it works:

Search existing ideas

Start by searching and reviewing ideas and requests to enhance a product or service. Take a look at ideas others have posted, and add a comment, vote, or subscribe to updates on them if they matter to you. If you can't find what you are looking for,

Post your ideas
  1. Post an idea.

  2. Get feedback from the IBM team and other customers to refine your idea.

  3. Follow the idea through the IBM Ideas process.


Specific links you will want to bookmark for future use

Welcome to the IBM Ideas Portal (https://www.ibm.com/ideas) - Use this site to find out additional information and details about the IBM Ideas process and statuses.

IBM Unified Ideas Portal (https://ideas.ibm.com) - Use this site to view all of your ideas, create new ideas for any IBM product, or search for ideas across all of IBM.

ideasibm@us.ibm.com - Use this email to suggest enhancements to the Ideas process or request help from IBM for submitting your Ideas.


Status Delivered
Workspace DataPower Gateway
Created by Guest
Created on Oct 3, 2022

Update SSH Host Key Ciphers and algorithms Sha-256/512

We are running Data Power Gateway appliances, these the supply the security we use for connectivity to all our trading partners, one trading partner that we connect with uses AWS and AWS have recently updated their security policy that now requires the use of more secure cipher/algorithms. AWS now require the use of rss-sha-256 and rsa-sha-512 hostkey algorithms. The issue is that Data Power does not currently support these, we have in this case been able to communicate with AWS to lower their requirement on security in this case as we just can not use those ciphers/algs.

The connection protocol in this particular use case was SSH, we connect to a growing number of AWS platforms and SSH is a very widely used protocol.

It seems silly to be asking IBM to add higher levels of security to an appliance that is meant for high levels of security. we also can not be asking AWS to break their security policies each time that we need to connect to a trading partner host in AWS.


These SSH ciphers/algorithms really must be updated.


Thanks

Richard

Idea priority High
  • Admin
    Ulas Cubuk
    Reply
    |
    Feb 26, 2024

    Support for rsa-sha2-256 and rsa-sha2-512 hostkey algorithms has been added in the current Continuous Delivery (CD) release.(10.5.1)

    This support is targeted to be included in the next major Long Term Support (LTS) firmware release.