SV-223227r1056177_rule
V-223227
SRG-APP-000412-NDM-000331
JUSX-DM-000150
CAT I
10
Configure SSH confidentiality options to comply with DOD requirements.
[edit]
set system services ssh protocol-version v2
set system services ssh ciphers aes256-ctr
set system services ssh ciphers aes192-ctr
set system services ssh ciphers aes128-ctr
set system services ssh macs hmac-sha2-512
set system services ssh macs hmac-sha2-256
set system services ssh key-exchange ecdh-sha2-nistp521
set system services ssh key-exchange ecdh-sha2-nistp384
set system services ssh key-exchange ecdh-sha2-nistp256
Verify SSHv2, AES ciphers, and key-exchange commands are configured to protect confidentiality.
[edit]
show system services ssh
If SSHv2 is not configured to use AES ciphers and key-exchange commands, this is a finding.
V-223227
False
JUSX-DM-000150
Verify SSHv2, AES ciphers, and key-exchange commands are configured to protect confidentiality.
[edit]
show system services ssh
If SSHv2 is not configured to use AES ciphers and key-exchange commands, this is a finding.
M
4098