SV-80751r1_rule
V-66261
SRG-APP-000412-NDM-000331
HFFS-ND-000117
CAT II
10
Configure the HP FlexFabric Switch to implement cryptographic mechanisms to protect the confidentiality of nonlocal maintenance and diagnostic communications.
Generate local RSA key pairs on the SSH server:
[HP] public-key local create rsa
Enable the SSH server function:
[HP] ssh server enable
Enable the SFTP server function:
[HP] sftp server enable
Configure the user interfaces for SSH clients:
[HP] user-interface vty 0 63
[HP-ui-vty0-63] authentication-mode scheme
Configure a local device management user, assign password and enable service-type SSH:
[HP] local-user admin
[HP-luser-admin] password simple xxxxxx
[HP-luser-admin] service-type ssh
Determine if the HP FlexFabric Switch implements cryptographic mechanisms to protect the confidentiality of nonlocal maintenance and diagnostic communications.
[HP] display ssh server status
SSH server: Enable
SSH version : 2.0
SSH authentication-timeout : 60 second(s)
SSH server key generating interval : 0 hour(s)
SSH authentication retries : 3 time(s)
SFTP server: Enable
SFTP Server Idle-Timeout: 10 minute(s)
Netconf server: Disable
[HP] display current | i sftp
sftp server enable
If SSH and SFTP protocols are not configured for nonlocal device maintenance , this is a finding.
V-66261
False
HFFS-ND-000117
Determine if the HP FlexFabric Switch implements cryptographic mechanisms to protect the confidentiality of nonlocal maintenance and diagnostic communications.
[HP] display ssh server status
SSH server: Enable
SSH version : 2.0
SSH authentication-timeout : 60 second(s)
SSH server key generating interval : 0 hour(s)
SSH authentication retries : 3 time(s)
SFTP server: Enable
SFTP Server Idle-Timeout: 10 minute(s)
Netconf server: Disable
[HP] display current | i sftp
sftp server enable
If SSH and SFTP protocols are not configured for nonlocal device maintenance , this is a finding.
M
2971