SV-279620r1192503_rule
V-279620
SRG-OS-000125-GPOS-00065
NXAC-OS-000184
CAT I
10
Configure SSH.
1. For AOS, configure SSH, then restart the SSH for the changes to take effect.
$ sudo salt-call state.sls security/CVM/sshdCVM
$ sudo systemctl restart sshd
2. For Prism Central, configure SSH, then restart the SSH for the changes to take effect.
$ sudo salt-call state.sls security/PCVM/sshdPCVM
$ sudo systemctl restart sshd
3. For Files, configure SSH, then restart the SSH for the changes to take effect.
$ sudo salt-call state.sls security/AFS/sshdAFS
$ sudo systemctl restart sshd
4. For AHV configure SSH, then restart the SSH for the changes to take effect.
$ sudo salt-call state.sls security/KVM/sshdKVM
$ sudo systemctl restart sshd
Verify Nutanix OS is configured to use only MACs employing FIPS 140-3-approved algorithms using the following command.
$ sudo grep -i ciphers /etc/crypto-policies/back-ends/opensshserver.config
CRYPTO_POLICY=Ciphers=aes256-ctr,aes192-ctr,aes128-ctr,aes256-gcm@openssh.com,aes128-gcm@openssh.com
If the cipher entries in the "opensshserver.config" file have any hashes other than shown here, the order differs from the example above, or they are missing or commented out, this is a finding.
V-279620
False
NXAC-OS-000184
Verify Nutanix OS is configured to use only MACs employing FIPS 140-3-approved algorithms using the following command.
$ sudo grep -i ciphers /etc/crypto-policies/back-ends/opensshserver.config
CRYPTO_POLICY=Ciphers=aes256-ctr,aes192-ctr,aes128-ctr,aes256-gcm@openssh.com,aes128-gcm@openssh.com
If the cipher entries in the "opensshserver.config" file have any hashes other than shown here, the order differs from the example above, or they are missing or commented out, this is a finding.
M
5730