SV-260531r1208689_rule
V-260531
SRG-OS-000033-GPOS-00014
UBTU-22-255050
CAT II
10
Configure the SSH server to only implement FIPS-approved ciphers.
Add or modify the following line in the "/etc/ssh/sshd_config" file:
Ciphers aes256-ctr,aes256-gcm@openssh.com,aes128-ctr,aes128-gcm@openssh.com
Restart SSH for the changes to take effect:
$ sudo systemctl restart ssh
Verify the SSH server is configured to only implement FIPS-approved ciphers with the following command:
$ sudo /usr/sbin/sshd -dd 2>&1 | awk '/filename/ {print $4}' | tr -d '\r' | tr '\n' ' ' | xargs sudo grep -iH 'ciphers'
/etc/ssh/sshd_config:Ciphers aes256-ctr,aes256-gcm@openssh.com,aes128-ctr,aes128-gcm@openssh.com
If "Ciphers" does not contain only the ciphers "aes256-ctr,aes256-gcm@openssh.com,aes128-ctr,aes128-gcm@openssh.com", is commented out, is missing, or conflicting results are returned, this is a finding.
V-260531
False
UBTU-22-255050
Verify the SSH server is configured to only implement FIPS-approved ciphers with the following command:
$ sudo /usr/sbin/sshd -dd 2>&1 | awk '/filename/ {print $4}' | tr -d '\r' | tr '\n' ' ' | xargs sudo grep -iH 'ciphers'
/etc/ssh/sshd_config:Ciphers aes256-ctr,aes256-gcm@openssh.com,aes128-ctr,aes128-gcm@openssh.com
If "Ciphers" does not contain only the ciphers "aes256-ctr,aes256-gcm@openssh.com,aes128-ctr,aes128-gcm@openssh.com", is commented out, is missing, or conflicting results are returned, this is a finding.
M
5594