4.5.3.18 sshd_config, ssh_config: ReKeyLimit

Information

This variable specifies the maximum amount of data that may be transmitted before the session key is renegotiated, optionally followed by a maximum amount of time that may pass before the session key is renegotiated.

Rationale:

This recommendation is based on the guidelines outlined in Chapter 9 in [RFC4253], i.e. the recommendation is to release/renew Session keys after one hour or after the transfer of one gigabyte (depending on whichever comes first).

Solution

Edit the /etc/ssh/sshd_config file to set the parameter as follows:

RekeyLimit 1G 3600

Default Value:

RekeyLimit default None

See Also

https://workbench.cisecurity.org/benchmarks/13069

Item Details

Category: ACCESS CONTROL, CONFIGURATION MANAGEMENT, IDENTIFICATION AND AUTHENTICATION, MAINTENANCE, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|AC-17(2), 800-53|CM-7, 800-53|IA-5, 800-53|IA-5(1), 800-53|MA-4, 800-53|SC-8, 800-53|SC-8(1), CSCv7|9.2, CSCv7|14.4

Plugin: Unix

Control ID: 28ff33b65f6d1567123c0f7691c73428a4c10821ea2542e040bdfd7e143d4a51