SV-268089r1130978_rule
V-268089
SRG-OS-000033-GPOS-00014
ANIX-00-000150
CAT I
10
Configure NixOS to use only ciphers employing FIPS 140-3 approved algorithms.
To configure OpenSSH, add the following Nix code to the NixOS Configuration, usually located in /etc/nixos/configuration.nix or /etc/nixos/flake.nix:
services.openssh.setting.Ciphers = [
"aes256-ctr"
"aes192-ctr"
"aes128-ctr"
];
Rebuild and switch to the new NixOS configuration:
$ sudo nixos-rebuild switch
Verify NixOS is configured to only use ciphers employing FIPS 140-3 approved algorithms with the following command:
$ grep Ciphers /etc/ssh/sshd_config
Ciphers aes256-ctr,aes192-ctr,aes128-ctr
If the cipher entries in the "sshd_config" file have any ciphers other than "aes256-ctr,aes192-ctr,aes128-ctr", the order differs from the example above, or they are missing or commented out, this is a finding.
V-268089
False
ANIX-00-000150
Verify NixOS is configured to only use ciphers employing FIPS 140-3 approved algorithms with the following command:
$ grep Ciphers /etc/ssh/sshd_config
Ciphers aes256-ctr,aes192-ctr,aes128-ctr
If the cipher entries in the "sshd_config" file have any ciphers other than "aes256-ctr,aes192-ctr,aes128-ctr", the order differs from the example above, or they are missing or commented out, this is a finding.
M
5658