Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

Bitbucket v4.14.4: can not disable ssh ciphers

Kiril July 25, 2019

Due to vulnerables in some ssh ciphers, I put this in bitbucket.properties :

plugin.ssh.disabled.ciphers=arcfour128,arcfour256,aes128-cbc,aes192-cbc,aes256-cbc,3des-cbc,blowfish-cbc

After that, these ciphere still enabled:

arcfour256, aes192-cbc, aes256-cbc

The command used to check:

nmap --script ssh2-enum-algos -sV -p 7999 localhost

Why some ciphers from the list still enabled?

1 answer

0 votes
Christian Glockner
Atlassian Team
Atlassian Team members are employees working across the company in a wide variety of roles.
July 26, 2019

Hi Kiril,

Did you restart Bitbucket Server after the change?

Cheers,

Christian

Premier Support Engineer

Atlassian

Kiril July 29, 2019

Yes Christian, I restart Bitbucket Server after any change in bitbucket.properties .

After restart some cipheres disappeared, but not all from the list.

Suggest an answer

Log in or Sign up to answer
TAGS
AUG Leaders

Atlassian Community Events