SV-223227r513370_rule
V-223227
SRG-APP-000412-NDM-000331
JUSX-DM-000150
CAT II
10
Configure SSH confidentiality options to comply with DoD requirements.
[edit]
set system services ssh protocol-version v2
set system services ssh ciphers aes256-ctr
set system services ssh ciphers aes256-cbc
set system services ssh ciphers aes192-ctr
set system services ssh ciphers aes192-cbc
set system services ssh ciphers aes128-ctr
set system services ssh ciphers aes128-cbc
set system services ssh key-exchange dh-group14-sha1
set system services ssh key-exchange group-exchange-sha2
set system services ssh key-exchange ecdh-sha2-nistp256
set system services ssh key-exchange ecdh-sha2-nistp384
set system services ssh key-exchange ecdh-sha2-nistp521
Verify SSHv2, AES ciphers, and key-exchange commands are configured to protect confidentiality.
[edit]
show system services ssh
If SSHv2, AES ciphers, and key-exchange commands are not configured to protect confidentiality, this is a finding.
V-223227
False
JUSX-DM-000150
Verify SSHv2, AES ciphers, and key-exchange commands are configured to protect confidentiality.
[edit]
show system services ssh
If SSHv2, AES ciphers, and key-exchange commands are not configured to protect confidentiality, this is a finding.
M
4098