{"id":58694,"date":"2020-03-18T11:15:05","date_gmt":"2020-03-18T19:15:05","guid":{"rendered":"https:\/\/devblogs.microsoft.com\/devops\/?p=58694"},"modified":"2020-03-18T11:15:05","modified_gmt":"2020-03-18T19:15:05","slug":"supporting-sha-2-algorithm-in-ssh-on-azure-devops","status":"publish","type":"post","link":"https:\/\/devblogs.microsoft.com\/devops\/supporting-sha-2-algorithm-in-ssh-on-azure-devops\/","title":{"rendered":"Supporting SHA-2 algorithm in SSH on Azure DevOps"},"content":{"rendered":"<p>With the release of <a href=\"http:\/\/www.openssh.com\/txt\/release-8.2\">OpenSSH 8.2<\/a> last month, connections to SSH servers using SHA-1 was disabled by default in the OpenSSH client. We understand that this move helps improve the security of SSH connections, by encouraging all users to adopt the SHA-2 class of algorithms, generally considered safer. However, this resulted in OpenSSH users not being able to connect to Azure DevOps, since Azure DevOps only supported SHA-1 class algorithms. Workaround was to use a flag to force the client to fall back to SHA-1.<\/p>\n<p>We&#8217;ve now remedied the situation by enabling support for a SHA-2 class key exchange algorithm &#8211; \u2018diffie-hellman-group-exchange-sha256\u2019. This will now allow users to connect to Azure DevOps with the OpenSSH 8.2 client without additional steps.<\/p>\n<p>We introduced this change to the Azure DevOps Services on March 6, 2020. We&#8217;re now bringing the same capability to Azure DevOps Server 2019 in the April 2020 patch. And we&#8217;re actively working to bring this to Azure DevOps Server 2018 via a patch in the next couple of months.<\/p>\n<p>Thank you for your patience as we work through this.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>With the release of OpenSSH 8.2 last month, connections to SSH servers using SHA-1 was disabled by default in the OpenSSH client. We understand that this move helps improve the security of SSH connections, by encouraging all users to adopt the SHA-2 class of algorithms, generally considered safer. However, this resulted in OpenSSH users not [&hellip;]<\/p>\n","protected":false},"author":142,"featured_media":45953,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[228,224,225,251],"tags":[],"class_list":["post-58694","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-admin-licensing","category-azure","category-git","category-security"],"acf":[],"blog_post_summary":"<p>With the release of OpenSSH 8.2 last month, connections to SSH servers using SHA-1 was disabled by default in the OpenSSH client. We understand that this move helps improve the security of SSH connections, by encouraging all users to adopt the SHA-2 class of algorithms, generally considered safer. However, this resulted in OpenSSH users not [&hellip;]<\/p>\n","_links":{"self":[{"href":"https:\/\/devblogs.microsoft.com\/devops\/wp-json\/wp\/v2\/posts\/58694","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/devblogs.microsoft.com\/devops\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/devblogs.microsoft.com\/devops\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/devops\/wp-json\/wp\/v2\/users\/142"}],"replies":[{"embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/devops\/wp-json\/wp\/v2\/comments?post=58694"}],"version-history":[{"count":0,"href":"https:\/\/devblogs.microsoft.com\/devops\/wp-json\/wp\/v2\/posts\/58694\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/devops\/wp-json\/wp\/v2\/media\/45953"}],"wp:attachment":[{"href":"https:\/\/devblogs.microsoft.com\/devops\/wp-json\/wp\/v2\/media?parent=58694"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/devops\/wp-json\/wp\/v2\/categories?post=58694"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/devops\/wp-json\/wp\/v2\/tags?post=58694"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}