5.2.20 Ensure system-wide crypto policy is not over-ridden

Information

System-wide Crypto policy can be over-ridden or opted out of for openSSH Over-riding or opting out of the system-wide crypto policy could allow for the use of less secure Ciphers, MACs, KexAlgoritms and GSSAPIKexAlgorithsm

Solution

Run the following commands: # sed -ri "s/^s*(CRYPTO_POLICYs*=.*)$/# 1/" /etc/sysconfig/sshd # systemctl reload sshd

See Also

https://workbench.cisecurity.org/files/2518

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-13, CSCv7|14.4

Plugin: Unix

Control ID: 8b0a12bf2df32786fb954c636b5485e51c5e4febfe4815f17f188dd15f5d5b02