IBM Support

Fix a PuTTY Fatal Error of "Couldn't agree a client-to-server cipher"

Troubleshooting


Problem

When trying to connect to a Guardium appliance of v.9.0 patch 200 or later using the SSH development tool, PuTTY, the following PuTTY fatal error message appears.

Cause


Guardium appliances of version v9.0 patch 200 or later set the default ciphers for SSH to be aes128-ctr, aes192-ctr or aes256-ctr. This is an advanced mode of the AES cipher that is more recent than other modes of AES.

Diagnosing The Problem

If you connect and see the dialog, use the "About" button on the main PuTTY window to see the version:




If this version is 0.58 or earlier, then AES in CTR mode is not available.

Resolving The Problem

Install the most recent version of PuTTY.

[{"Product":{"code":"SSMPHH","label":"IBM Security Guardium"},"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Component":"Not Applicable","Platform":[{"code":"PF002","label":"AIX"},{"code":"PF010","label":"HP-UX"},{"code":"PF016","label":"Linux"},{"code":"PF027","label":"Solaris"},{"code":"PF033","label":"Windows"},{"code":"PF035","label":"z\/OS"}],"Version":"9.1;9.0","Edition":"All Editions","Line of Business":{"code":"LOB24","label":"Security Software"}}]

Document Information

Modified date:
16 July 2018

UID

swg21685848