The crypto hardware devices available on zSeries machines implement certain algorithms. Although SSH Tectia Server for IBM z/OS includes most of the algorithms available in SSH Tectia Client and Server products on other platforms, using hardware acceleration is recommended because it will reduce the CPU usage.
Recommended algorithms on System z9 if crypto hardware is enabled:
Cipher: 128-bit AES and 3DES (aes128-cbc,3des-cbc)
MAC: SHA-1 (hmac-sha1)
Recommended algorithms on other systems if crypto hardware is enabled:
Cipher: 3DES (3des-cbc)
MAC: SHA-1 (hmac-sha1)
Recommended algorithms if crypto hardware is not enabled or not installed:
Reduce Secure Shell risk. Get to know the NIST 7966.
The NISTIR 7966 guideline from the Computer Security Division of NIST is a direct call to action for organizations regardless of industry and is a mandate for the US Federal government. Download now
ISACA Practitioner Guide for SSH
With contributions from practitioners, specialists and SSH.COM experts, the ISACA “SSH: Practitioner Considerations” guide is vital best practice from the compliance and audit community. Download now