SV-253911r1167978_rule
V-253911
SRG-APP-000179-NDM-000265
JUEX-NM-000340
CAT I
10
Configure the password format, SSH algorithms, and the RNG to use only FIPS-validated algorithms.
1. Enter configuration mode.
2. Configure the password format.
3. Configure the SSH algorithms.
4. Configure the RNG.
5. Commit the configuration.
user@host> configure
user@host# set system login password format <sha256|sha512>
user@host# set system services ssh ciphers aes256-ctr
user@host# set system services ssh ciphers aes256-cbc
user@host# set system services ssh macs hmac-sha2-512
user@host# set system services ssh macs hmac-sha2-256
user@host# set system services ssh key-exchange ecdh-sha2-nistp521
user@host# set system services ssh key-exchange ecdh-sha2-nistp384
user@host# set system services ssh key-exchange ecdh-sha2-nistp256
user@host# set system rng hmac-drbg
user@host# commit
Verify the password format, and that SSH uses FIPS-validated algorithms and a random number generator (RNG) as shown in the following example configuration:
user@host> show configuration system
login {
password {
:
format <sha256|sha-512>;
}
}
services {
ssh {
:
ciphers [ aes256-ctr aes256-cbc];
macs [ hmac-sha2-512 hmac-sha2-256 ];
key-exchange [ ecdh-sha2-nistp521 ecdh-sha2-nistp384 ecdh-sha2-nistp256 ];
:
}
}
rng {
hmac-drbg;
}
If the network device is not configured to use FIPS 140-2/140-3-validated authentication algorithms, this is a finding.
V-253911
False
JUEX-NM-000340
Verify the password format, and that SSH uses FIPS-validated algorithms and a random number generator (RNG) as shown in the following example configuration:
user@host> show configuration system
login {
password {
:
format <sha256|sha-512>;
}
}
services {
ssh {
:
ciphers [ aes256-ctr aes256-cbc];
macs [ hmac-sha2-512 hmac-sha2-256 ];
key-exchange [ ecdh-sha2-nistp521 ecdh-sha2-nistp384 ecdh-sha2-nistp256 ];
:
}
}
rng {
hmac-drbg;
}
If the network device is not configured to use FIPS 140-2/140-3-validated authentication algorithms, this is a finding.
M
5477