SV-279536r1192381_rule
V-279536
SRG-OS-000250-GPOS-00093
NXAC-OS-000013
CAT I
10
Configure SSH.
1. For AOS, configure SSH, then restart the SSH for the changes to take effect.
$ sudo salt-call state.sls security/CVM/sshdCVM
$ sudo systemctl restart sshd
2. For Prism Central, configure SSH, then restart the SSH for the changes to take effect.
$ sudo salt-call state.sls security/PCVM/sshdPCVM
$ sudo systemctl restart sshd
3. For Files, configure SSH, then restart the SSH for the changes to take effect.
$ sudo salt-call state.sls security/AFS/sshdAFS
$ sudo systemctl restart sshd
Note: For AHV, this requirement is Not Applicable.
Verify AOS, Prism Central, and Files OS VMs are configured to only use DOD-approved TLS encryption using the following command.
$ sudo grep -i MinProtocol /etc/crypto-policies/back-ends/opensslcnf.config
TLS.MinProtocol = TLSv1.2
DTLS.MinProtocol = DTLSv1.2
If the "TLS.MinProtocol" is not set to "TLVSv1.2" (or later) or the "DTLS.Min.Protocol" is not set to "DTLSv1.2", this is a finding.
V-279536
False
NXAC-OS-000013
Note: For AHV, this requirement is Not Applicable.
Verify AOS, Prism Central, and Files OS VMs are configured to only use DOD-approved TLS encryption using the following command.
$ sudo grep -i MinProtocol /etc/crypto-policies/back-ends/opensslcnf.config
TLS.MinProtocol = TLSv1.2
DTLS.MinProtocol = DTLSv1.2
If the "TLS.MinProtocol" is not set to "TLVSv1.2" (or later) or the "DTLS.Min.Protocol" is not set to "DTLSv1.2", this is a finding.
M
5730