Key exchange failed, how to clear cache?

Need help with FileZilla Client? Something does not work as expected? In this forum you may find an answer.

Moderator: Project members

Post Reply
500 Command not understood
Posts: 1
Joined: 2020-02-10 16:44
First name: T

Key exchange failed, how to clear cache?

#1 Post by SHADOWSTRIKE1 » 2020-02-10 19:13

Hey everybody, first time posting here, and hoping someone can point me in the right direction.

So at work we had to make some changes on our SFTP server for PCI DSS 3.2 compliance, which included removing things such as hmac-md5, hmac-md5-96, hmac-sha1, and hmac-sha1-96 hashing algorithms, 3des-cbc, blowfish-cbc, and cast128-cbc encryption algorithms, and diffie-hellman-group1-sha1 and diffie-hellman-group14-sha1 key exchange algorithms.

We performed this over the weekend during a maintenance period, and I was able to successfully connect to the server after the change. However, we had a number of clients that couldn't connect this morning. They were reporting "key exchange failed" errors. We went and rolled back the changes, and they were able to connect again. My running theory is that they had one of the removed key exchanges cached, and failed when trying to connect using those removed algorithms. I figured it would go on to a higher encryption algorithm instead of failing, but here we are.

Has anyone had a similar problem when updating their algorithms? Is there an easy way to clear out that cache?

User avatar
Site Admin
Posts: 33122
Joined: 2004-02-23 20:49
First name: Tim
Last name: Kosse

Re: Key exchange failed, how to clear cache?

#2 Post by botg » 2020-02-11 08:28

There is no such cache in FileZilla.

Post Reply