arthepsy/ssh-audit

Prefer server order for ciphers

Opened this issue · 2 comments

It exists for TLS, not sure if it exists for SSH?

Good question. It exists (see below) and actually it's one of improvements I've planed. Haven't just figured what would be the best way to show that in output.

From https://tools.ietf.org/html/rfc4253:

Each supported (allowed) algorithm MUST be listed in order of preference, from most to least.

Maybe simply show the optimized Ciphers line in addition to the existing output? It would be easier to apply to the server conf, also.