AOSX-12-000570 - The OS X system must implement NSA-approved cryptography to protect classified information in accordance with applicable federal laws, Executive Orders, directives, policies, regulations, and standards.

Information

Use of weak or untested encryption algorithms undermines the purposes of using encryption to protect data. The operating system must implement cryptographic modules adhering to the higher standards approved by the federal government since this provides assurance they have been tested and validated.

Satisfies: SRG-OS-000112-GPOS-00057, SRG-OS-000113-GPOS-00058, SRG-OS-000396-GPOS-00176

Solution

To ensure that 'Protocol 2' is used by sshd, run the following command:

/usr/bin/sudo /usr/bin/sed -i.bak 's/.*Protocol.*/Protocol 2/' /etc/ssh/sshd_config

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Apple_OS_X_10-12_V1R6_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7, CAT|II, CCI|CCI-001941, CCI|CCI-001942, CCI|CCI-002450, CSCv6|9.1, Rule-ID|SV-90761r1_rule, STIG-ID|AOSX-12-000570, Vuln-ID|V-76073

Plugin: Unix

Control ID: 6f33c8a9f65b765181c145ba215705dfb052de57987ccc2c684d79b7284586cd