Uploaded image for project: 'TrueNAS'
  1. TrueNAS
  2. NAS-101605

SSH Service Fails to start with "extra options" enabled

    XMLWordPrintable

    Details

      Description

      Recently upgraded from 11.1-U7 to latest 11.2-U3.

      SSH service wouldn't initiated on startup. Restarting service errors out with:
      root: /usr/local/etc/rc.d/openssh: WARNING: failed precmd routine for openssh

      Removed "Extra Options" under SSH service settings:
      Ciphers 3des-cbc,aes128-cbc,aes192-cbc,aes256-cbc,aes128-ctr,aes192-ctr,aes256-ctr,aes128-gcm@openssh.com,aes256-gcm@openssh.com,arcfour,arcfour128,arcfour256,blowfish-cbc,cast128-cbc,chacha20-poly1305@openssh.com
      KexAlgorithms curve25519-sha256@libssh.org,diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1,diffie-hellman-group-exchange-sha256,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521

      This resolved the issue.

      This is a reoccurrance of a bug previous logged during 11.0 pre-release. 25068 was the ID on the previous bug system. Bug tracker link is inactive, but here is the link to the official post:

      link title

      I believe it would be beneficial to retain this functionality, and even though deprecated ciphers and algorithms may be unsafe for traversal over public internet, it can provide a performance benefit when utilized on internal network infrastructure. With correct hardware and cipher its possible to saturate most networks interfaces. Additionally, replicating/migrating data away from older linux systems (that are no longer maintained) using remote replication is far more convenient than driving over and plugging in a drive.

      Thank you.

       

       

        Attachments

          Attachments

            JEditor

              Activity

                People

                Assignee:
                waqar Waqar Ahmed
                Reporter:
                Kruger Jorgen Kruger
                Votes:
                0 Vote for this issue
                Watchers:
                3 Start watching this issue

                  Dates

                  Created:
                  Updated: