OpenSSH 7.1 and Mikrotik

Crappy SSH implementations (like Mikrotik) support only old and broken ciphers that are now blocked by default in openssh client.

Add this to your .ssh/config.

    PubkeyAcceptedKeyTypes ssh-rsa,ssh-dss*
    KexAlgorithms +diffie-hellman-group1-sha1

DH params too short

Edit DH_GRP_MIN in dh.h. I have not found any runtime config option for this.

