Bug ID 800193: Update OpenSSH to version 7 or later for disabling of DSA keys

Last Modified: Nov 07, 2022

Bug Tracker

Affected Product:  See more info
BIG-IP TMOS(all modules)

Known Affected Versions:
13.1.0, 13.1.0.1, 13.1.0.2, 13.1.0.3, 13.1.0.4, 13.1.0.5, 13.1.0.6, 13.1.0.7, 13.1.0.8, 13.1.1, 13.1.1.2, 13.1.1.3, 13.1.1.4, 13.1.1.5, 13.1.3, 13.1.3.1, 13.1.3.2, 13.1.3.3, 13.1.3.4, 13.1.3.5

Fixed In:
13.1.3.6

Opened: Jun 28, 2019
Severity: 4-Minor

Symptoms

Current OpenSSH version 6.6.1p1 in BIG-IP v13.1.x does not allow for disabling DSA Key. Lack of this feature causes failure audits due to allowing DSA keys to authenticate to the BIG-IP system.

Impact

Lack of this feature(disabling DSA Key) causes audit failures due to allowing DSA keys to authenticate to the BIG-IP system.

Conditions

The issue can be seen on BIG-IP software that has OpenSSH version 6.6.

Workaround

None.

Fix Information

This version has updated OpenSSH to version 7 for disabling DSA keys.

Behavior Change