SV-100361r1_rule
V-89711
SRG-OS-000125-GPOS-00065
VRAU-SL-000760
CAT II
10
Update the "Ciphers" directive with the following command:
# sed -i "/^[^#]*Ciphers/ c\Ciphers aes256-ctr,aes128-ctr" /etc/ssh/sshd_config
Save and close the file.
Restart the sshd process:
# service sshd restart
Check the SSH daemon configuration for DoD-approved encryption to protect the confidentiality of SSH remote connections by performing the following commands:
Check the "Ciphers" setting in the "sshd_config" file.
# grep -i Ciphers /etc/ssh/sshd_config | grep -v '#'
The output must contain either nothing or any number of the following algorithms:
aes128-ctr, aes256-ctr.
If the output contains an algorithm not listed above, this is a finding.
Expected Output:
Ciphers aes256-ctr,aes128-ctr
V-89711
False
VRAU-SL-000760
Check the SSH daemon configuration for DoD-approved encryption to protect the confidentiality of SSH remote connections by performing the following commands:
Check the "Ciphers" setting in the "sshd_config" file.
# grep -i Ciphers /etc/ssh/sshd_config | grep -v '#'
The output must contain either nothing or any number of the following algorithms:
aes128-ctr, aes256-ctr.
If the output contains an algorithm not listed above, this is a finding.
Expected Output:
Ciphers aes256-ctr,aes128-ctr
M
3459