Qualys vulnerability SSH server public key too small for NetApp FAS and AFF SANs

This is a quick post on how to address the Qualys vulnerability SSH server public key too small for NetApp FAS and AFF SANs.  Described in this article 

First run the below to see the current security configuration:

security config show

 

 

Qualys vulnerability SSH server public key too small for NetApp FAS and AFF SANs-1a

Now run the below to enable fips and accept the x3 prompts:

security config modify -interface SSL -is-fips-enabled true

 

 

Qualys vulnerability SSH server public key too small for NetApp FAS and AFF SANs-2

Run security status show command again and you will see you need to reboot both nodes

Qualys vulnerability SSH server public key too small for NetApp FAS and AFF SANs-3

The easiest way to do this in a cluster is to login to the NetApp OnCommand Manager and go to High Availability under the cluster settings.  Lets reboot node 2 first by selecting the option under node 1 to take over node 2

Qualys vulnerability SSH server public key too small for NetApp FAS and AFF SANs-4

Click Takeover

Qualys vulnerability SSH server public key too small for NetApp FAS and AFF SANs-5

The process starts

Qualys vulnerability SSH server public key too small for NetApp FAS and AFF SANs-6

Node 2 goes offline while it is rebooted

Qualys vulnerability SSH server public key too small for NetApp FAS and AFF SANs-8

Continue to wait – although it gives the option to giveback do not click this

Qualys vulnerability SSH server public key too small for NetApp FAS and AFF SANs-10

Great, looks like all was successful! Node 2 was rebooted and back online.  You can re-home interfaces by going to Network>Interfaces>Send to home

Qualys vulnerability SSH server public key too small for NetApp FAS and AFF SANs-11

Start the process again but this time to reboot node 1, so elect node 2 and click take over node 1

Qualys vulnerability SSH server public key too small for NetApp FAS and AFF SANs-14

Again click Takeover

Qualys vulnerability SSH server public key too small for NetApp FAS and AFF SANs-15

Continue to wait

Qualys vulnerability SSH server public key too small for NetApp FAS and AFF SANs-16

Node 1 goes offline

Qualys vulnerability SSH server public key too small for NetApp FAS and AFF SANs-17

Wait until you see the message where nodes can take over before successful

Qualys vulnerability SSH server public key too small for NetApp FAS and AFF SANs-18

Run another security config show to see if the reboot is still needed. If not all is completed

Qualys vulnerability SSH server public key too small for NetApp FAS and AFF SANs-13

Leave a Reply

Your email address will not be published. Required fields are marked *