Earlier quoted context omitted.
I like it a lot ... I just dont know what to do about all my 'weak' results.
Generally they’re going to be for legacy ciphers/MACs/etc. If you don’t need them, you can turn them off. If you’re the only one accessing your servers, you can honestly just pick a single option for each based on the highest security option that’s supported by all your client devices. https://infosec.mozilla.org/guidelines/openssh.html is a good starting point. The lists of available options are sorted from left ->…
edit: thanks for that link - swiped their kex, ciphers and macs and didnt break anything (that I know of)