SV-279534r1192285_rule
V-279534
SRG-OS-000250-GPOS-00093
NXAC-OS-000010
CAT I
10
Configure SSH.
1. For AOS, configure SSH, then restart the SSH for the changes to take effect.
$ sudo salt-call state.sls security/CVM/sshdCVM
$ sudo systemctl restart sshd
2. For Prism Central, configure SSH, then restart the SSH for the changes to take effect.
$ sudo salt-call state.sls security/PCVM/sshdPCVM
$ sudo systemctl restart sshd
3. For Files, configure SSH, then restart the SSH for the changes to take effect.
$ sudo salt-call state.sls security/AFS/sshdAFS
$ sudo systemctl restart sshd
4. For AHV, configure SSH, then restart the SSH for the changes to take effect.
$ sudo salt-call state.sls security/KVM/sshdKVM
$ sudo systemctl restart sshd
Verify Nutanix OS is configured to use approved ciphers.
1. Configure AOS, Prism Central, and Files OS VMs to use only HMACs employing FIPS 140-3-approved algorithms for remote access using the following command.
$ sudo grep -i macs /etc/crypto-policies/back-ends/opensshserver.config
MACS=hmac-sha2-512,hmac-sha2-256,hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com
2. Verify AHV "Ciphers" configuration using the following command.
$ sudo grep -i ciphers /etc/ssh/sshd_config
Ciphers aes256-ctr
If unapproved ciphers are listed, the "Ciphers" keyword is missing, or the returned line is commented out, this is a finding.
V-279534
False
NXAC-OS-000010
Verify Nutanix OS is configured to use approved ciphers.
1. Configure AOS, Prism Central, and Files OS VMs to use only HMACs employing FIPS 140-3-approved algorithms for remote access using the following command.
$ sudo grep -i macs /etc/crypto-policies/back-ends/opensshserver.config
MACS=hmac-sha2-512,hmac-sha2-256,hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com
2. Verify AHV "Ciphers" configuration using the following command.
$ sudo grep -i ciphers /etc/ssh/sshd_config
Ciphers aes256-ctr
If unapproved ciphers are listed, the "Ciphers" keyword is missing, or the returned line is commented out, this is a finding.
M
5730