The Photon operating system must configure sshd to use approved encryption algorithms.
DISA Rule
SV-256486r958408_rule
Vulnerability Number
V-256486
Group Title
SRG-OS-000033-GPOS-00014
Rule Version
PHTN-30-000009
Severity
CAT III
CCI(s)
- CCI-000068 - Implement cryptographic mechanisms to protect the confidentiality of remote access sessions.
- CCI-001453 - Implement cryptographic mechanisms to protect the integrity of remote access sessions.
- CCI-002418 - Protect the confidentiality and/or integrity of transmitted information.
- CCI-002450 - Implement organization-defined types of cryptography for each specified cryptography use.
- CCI-002890 - Implement organization-defined cryptographic mechanisms to protect the integrity of nonlocal maintenance and diagnostic communications.
Weight
10
Fix Recommendation
Navigate to and open:
/etc/ssh/sshd_config
Ensure the "FipsMode" line is uncommented and set to the following:
FipsMode yes
At the command line, run the following command:
# systemctl restart sshd.service
Check Contents
At the command line, run the following command:
# sshd -T|&grep -i FipsMode
Expected result:
FipsMode yes
If the output does not match the expected result, this is a finding.
Vulnerability Number
V-256486
Documentable
False
Rule Version
PHTN-30-000009
Severity Override Guidance
At the command line, run the following command:
# sshd -T|&grep -i FipsMode
Expected result:
FipsMode yes
If the output does not match the expected result, this is a finding.
Check Content Reference
M
Target Key
5520