Our Products:   CompleteFTP  edtFTPnet/Free  edtFTPnet/PRO  edtFTPj/Free  edtFTPj/PRO
0 votes
26 views
ago in CompleteFTP by (165k points)
I've upgraded to 26.1.0.  When some clients attempt to connect, I see the error "DH generator g is not in the q-order subgroup".

1 Answer

0 votes
ago by (165k points)
Version 26.1.0 introduced a stricter validation of the Diffie-Hellman group parameters exchanged during SSH key negotiation. It is possible that some clients are still sending weak parameters, which is a security risk.

If your client is doing this, the easiest solution is to disable the DH group exchange methods in either the client or in CompleteFTP: diffie-hellman-group-exchange-sha1 and diffie-hellman-group-exchange-sha256. They are no longer the preferred key exchange mechanisms.

Categories

...