Uploaded image for project: 'Jenkins'
  1. Jenkins
  2. JENKINS-23812

Add configuration option to enable/disable ciphers used for sshd

      Our IT dept uses automated scanning tools to discover vulnerabilities. Having the CBC ciphers enabled for the ssh connection to jenkins throws warnings in the tools.

      I would like a configuration option to enable/disable particular ciphers, so that I could disable the cbc ciphers.

      Our IT dept is able to do their job better when scans are clean and not throwing flags up at management.

      This could be left as is, but allowing users the option to increase security at low implementation risk is almost always a good thing.

          [JENKINS-23812] Add configuration option to enable/disable ciphers used for sshd

          Gavin Swanson created issue -
          R. Tyler Croy made changes -
          Workflow Original: JNJira [ 156602 ] New: JNJira + In-Review [ 179344 ]

          Daniel Beck added a comment -

          Jenkins 2.37 threw out the obsolete ciphers.

          Daniel Beck added a comment - Jenkins 2.37 threw out the obsolete ciphers.
          Daniel Beck made changes -
          Resolution New: Cannot Reproduce [ 5 ]
          Status Original: Open [ 1 ] New: Resolved [ 5 ]
          Daniel Beck made changes -
          Labels Original: ciphers ssh sshd vulnerability New: ciphers ssh sshd

          Oleg Nenashev added a comment -

          The feature request is still there. It has to be done on the SSHD Module side, and Security Global Config or System props would be useful in this case

          Oleg Nenashev added a comment - The feature request is still there. It has to be done on the SSHD Module side, and Security Global Config or System props would be useful in this case
          Oleg Nenashev made changes -
          Resolution Original: Cannot Reproduce [ 5 ]
          Status Original: Resolved [ 5 ] New: Reopened [ 4 ]
          Oleg Nenashev made changes -
          Assignee New: Oleg Nenashev [ oleg_nenashev ]
          Oleg Nenashev made changes -
          Link New: This issue is related to JENKINS-39738 [ JENKINS-39738 ]
          Oleg Nenashev made changes -
          Assignee Original: Oleg Nenashev [ oleg_nenashev ]

            Unassigned Unassigned
            s7726 Gavin Swanson
            Votes:
            2 Vote for this issue
            Watchers:
            3 Start watching this issue

              Created:
              Updated: