ip ssh key-exchange-method dh-group1-sha1

Disables or re-enables diffie-hellman-group1-sha1 as the key-exchange method to establish an SSH connection.
Syntax
ip ssh key-exchange-method dh-group1-sha1
no ip ssh key-exchange-method dh-group1-sha1
Command Default

The diffie-hellman-group14-sha1 is used as the default key-exchange method. When the user disables diffie-hellman-group1-sha1 as the key-exchange method, the diffie-hellman-group14-sha1 takes over as the key-exchange method.

Modes

Global configuration mode

Usage Guidelines

The ip ssh key-exchange-method dh-group1-sha1 command is not supported in FIPS or CC mode.

The no form of the command disables diffie-hellman-group1-sha1 as the key-exchange method.

In FIPS mode, only diffie-helman-group-exchange-sha256 is supported and in common criteria(CC) mode, only diffie-hellman-group14-sha1 is supported.

Examples

The following example disables diffie-hellman-group1-sha1 as the key-exchange method.

device(config)# no ip ssh key-exchange-method dh-group1-sha1
History
Release version Command history
08.0.70 This command was introduced.