STIGQter STIGQter: STIG Summary: Riverbed NetIM OS Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 11 Sep 2025:

Ubuntu OS must configure the SSH daemon to use FIPS 140-2/140-3 approved ciphers to prevent the unauthorized disclosure of information and/or detect changes to information during transmission.

DISA Rule

SV-275624r1147922_rule

Vulnerability Number

V-275624

Group Title

SRG-OS-000033-GPOS-00014

Rule Version

RIIM-OS-255050

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the SSH server to only implement FIPS-approved ciphers.

Add or modify the following line in the "/etc/ssh/sshd_config" file:

Ciphers aes256-ctr,aes256-gcm@openssh.com,aes192-ctr,aes128-ctr,aes128-gcm@openssh.com

Restart the SSH server for the changes to take effect:

$ sudo systemctl restart sshd.service

Check Contents

Verify the SSH server is configured to only implement FIPS-approved ciphers with the following command:

$ sudo /usr/sbin/sshd -dd 2>&1 | awk '/filename/ {print $4}' | tr -d '\r' | tr '\n' ' ' | xargs sudo grep -iH 'ciphers'
/etc/ssh/sshd_config:Ciphers aes256-ctr,aes256-gcm@openssh.com,aes192-ctr,aes128-ctr,aes128-gcm@openssh.com

If "Ciphers" does not contain only the ciphers "aes256-ctr,aes256-gcm@openssh.com,aes192-ctr,aes128-ctr,aes128-gcm@openssh.com" in exact order, is commented out, is missing, or conflicting results are returned, this is a finding.

Vulnerability Number

V-275624

Documentable

False

Rule Version

RIIM-OS-255050

Severity Override Guidance

Verify the SSH server is configured to only implement FIPS-approved ciphers with the following command:

$ sudo /usr/sbin/sshd -dd 2>&1 | awk '/filename/ {print $4}' | tr -d '\r' | tr '\n' ' ' | xargs sudo grep -iH 'ciphers'
/etc/ssh/sshd_config:Ciphers aes256-ctr,aes256-gcm@openssh.com,aes192-ctr,aes128-ctr,aes128-gcm@openssh.com

If "Ciphers" does not contain only the ciphers "aes256-ctr,aes256-gcm@openssh.com,aes192-ctr,aes128-ctr,aes128-gcm@openssh.com" in exact order, is commented out, is missing, or conflicting results are returned, this is a finding.

Check Content Reference

M

Target Key

5706