Version covered: AitriumOS 2.2.7. AitriumOS uses the libssh2 1.11 SSH library. On Windows it uses the Windows cryptography API (CNG); on macOS it uses OpenSSL. The two platforms support different algorithm sets, so check both columns below.
How sites connect
- AitriumOS is an SSH-2 SFTP client. Each site’s workstation connects directly to the host and port configured in the trial’s integration. Traffic does not pass through Aitrium, and it cannot go through a web (HTTP) proxy.
- Connections come from each site’s public egress IP address. There is no fixed Aitrium address to allowlist. If your server restricts source addresses, each site must send you its egress addresses.
- If your host name resolves to several addresses, such as IPv6 and IPv4, AitriumOS 2.2.7 tries them one after another, in the order the site’s resolver returns them.
Supported algorithms
SSH uses the first algorithm in the client’s list that the server also supports. AitriumOS offers the algorithms below in this order of preference.- Integrated ciphers.
[email protected]and the AES-GCM ciphers include their own integrity protection, so no separate MAC is negotiated with them. - Strict key exchange. AitriumOS 2.2.7 supports the OpenSSH strict key exchange extension (
[email protected]), which mitigates the Terrapin attack. - Not supported: post-quantum hybrid key exchange (such as
sntrup761x25519-sha512ormlkem768x25519-sha256) and DSA host keys. Servers that offer post-quantum methods alongside the classic ones above are unaffected. - Older algorithms, such as SHA-1-based key exchange and MACs and CBC-mode ciphers, are still offered at the lowest preference so older servers keep working. A server that disables them is unaffected.
Recommended server settings
Servers that work with AitriumOS today need no changes for 2.2.7. AitriumOS 2.2.7 only adds algorithms and reorders its preferences; everything earlier versions could negotiate, including legacy
ssh-rsa host keys and SHA-1 key exchange and MACs, is still accepted. The settings below are guidance for new servers or when hardening an existing one.Changes in AitriumOS 2.2.7
A server that accepts only encrypt-then-MAC MACs requires AitriumOS 2.2.7 or later.
Authentication
RSA key signatures. AitriumOS signs RSA key logins with
rsa-sha2-512 or rsa-sha2-256. A server that accepts only the legacy ssh-rsa signature for key logins works if it advertises that restriction to clients (OpenSSH 9.7 or later does); on older servers, also accept rsa-sha2-256 or rsa-sha2-512 in PubkeyAcceptedAlgorithms.
Private key formats. PEM (-----BEGIN RSA PRIVATE KEY-----) works on every platform and is the recommended format. OpenSSH format (-----BEGIN OPENSSH PRIVATE KEY-----) is also accepted. On Windows, AitriumOS converts an OpenSSH-format key with the ssh-keygen tool from Windows’ OpenSSH Client feature, so each site’s workstation needs that feature installed. PuTTY .ppk keys are not accepted; export them in OpenSSH format with PuTTYgen first.
Credentials are configured by the trial organization and delivered encrypted to authorized site users. Sites do not enter or hold them. See Transfer credentials.
Traffic your server will see
Many workstations at one hospital can share a single public IP address. The limits above apply per workstation, so intrusion-prevention or ban rules (for example fail2ban) should allow for several workstations connecting from one address.
Troubleshooting from the server side
- Connection closes after the key exchange, before sign-in, with the reason
AitriumOS reachability check: this is the handshake-only check working as designed. - “No matching” key exchange, host key, cipher or MAC in your server log: compare your server’s enabled algorithms with Recommended server settings. Tell sites to update to AitriumOS 2.2.7 if your server accepts only encrypt-then-MAC MACs or only ChaCha20.
- No connection attempt in your log while a site reports “No response” or “refused the connection”: the traffic is blocked before it reaches your server, by the site’s outbound firewall or your own address restrictions.