GEN005505 - The SSH daemon must be configured to only use FIPS 140-2 approved ciphers

Information

DoD information systems are required to use FIPS 140-2 approved ciphers. SSHv2 ciphers meeting this requirement are 3DES and AES.

Solution

Edit the configuration file and remove any ciphers that do not meet the following: 3des-ctr or aes-NNN-ctr (NNN=128, 192 or 256).

If necessary, add the Ciphers entry with one or more of the above keyword values.

See Also

https://iasecontent.disa.mil/stigs/zip/U_HPUX_11-31_V1R19_STIG.zip

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-13, CAT|II, CCI|CCI-000068, Rule-ID|SV-35216r1_rule, STIG-ID|GEN005505, Vuln-ID|V-22458

Plugin: Unix

Control ID: 253b0ca2911b9f27b2cb5cf1c09b0f11e0ce3581d60c6a533a3914d78516ee47