STIGQter STIGQter: STIG Summary: Canonical Ubuntu 24.04 LTS Security Technical Implementation Guide Version: 1 Release: 6 Benchmark Date: 01 Jul 2026:

Ubuntu 24.04 LTS must configure the SSH daemon to use FIPS 140-3 approved ciphers to prevent the unauthorized disclosure of information and/or detect changes to information during transmission.

DISA Rule

SV-270667r1067107_rule

Vulnerability Number

V-270667

Group Title

SRG-OS-000033-GPOS-00014

Rule Version

UBTU-24-100820

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure Ubuntu 24.04 LTS to allow the SSH daemon to only implement FIPS-approved algorithms.

Add the following line (or modify the line to have the required value) to the "/etc/ssh/sshd_config" file (this file may be named differently or be in a different location if using a version of SSH that is provided by a third-party vendor):

Ciphers aes256-gcm@openssh.com,aes128-gcm@openssh.com,aes256-ctr,aes128-ctr

Restart the "sshd" service for changes to take effect:

$ sudo systemctl restart sshd

Check Contents

Verify that the SSH daemon is configured to implement only FIPS-approved algorithms with the following command:

$ sudo grep -r 'Ciphers' /etc/ssh/sshd_config*
Ciphers aes256-gcm@openssh.com,aes128-gcm@openssh.com,aes256-ctr,aes128-ctr

If any ciphers other than "Ciphers aes256-gcm@openssh.com,aes128-gcm@openssh.com,aes256-ctr,aes128-ctr" are listed, the "Ciphers" keyword is missing, or the returned line is commented out, or if multiple conflicting ciphers are returned, this is a finding.

Vulnerability Number

V-270667

Documentable

False

Rule Version

UBTU-24-100820

Severity Override Guidance

Verify that the SSH daemon is configured to implement only FIPS-approved algorithms with the following command:

$ sudo grep -r 'Ciphers' /etc/ssh/sshd_config*
Ciphers aes256-gcm@openssh.com,aes128-gcm@openssh.com,aes256-ctr,aes128-ctr

If any ciphers other than "Ciphers aes256-gcm@openssh.com,aes128-gcm@openssh.com,aes256-ctr,aes128-ctr" are listed, the "Ciphers" keyword is missing, or the returned line is commented out, or if multiple conflicting ciphers are returned, this is a finding.

Check Content Reference

M

Target Key

5673