SV-81687r1_rule
V-67197
SRG-APP-000179-NDM-000265
AMLS-NM-200825
CAT II
10
Enable FIPS restrictions via the following commands:
Enable
Configure
Management ssh
Fips restrictions
Exit
Additionally, the switch should be configured to use its Hardware Random Number Generator as a source of entropy for the SSH protocol. To enable this, configure:
Enable
Configure
Management security
Entropy source hardware
Once this has been changed, regenerate the SSH RSA Keys with:
Reset ssh hostkey rsa
Review the device configuration via the “show running-config” command for the following statement:
management ssh
fips restrictions
If this statement is not present, this is a finding.
V-67197
False
AMLS-NM-200825
Review the device configuration via the “show running-config” command for the following statement:
management ssh
fips restrictions
If this statement is not present, this is a finding.
M
2825