GEN005510 - The SSH client must be configured to only use FIPS 140-2 approved ciphers

Information

DoD information systems are required to use FIPS 140-2 approved ciphers. SSHv2 ciphers meeting this requirement are 3DES and AES.

Solution

Edit the configuration file and remove any ciphers that do not meet the following- 3des-ctr or aes-NNN-ctr (NNN=128, 192 or 256). If necessary, add the Ciphers entry with one or more of the above keyword values.

See Also

https://iasecontent.disa.mil/stigs/zip/U_HPUX_11-31_V1R19_STIG.zip

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-13, CAT|II, CCI|CCI-000068, Rule-ID|SV-35188r1_rule, STIG-ID|GEN005510, Vuln-ID|V-22461

Plugin: Unix

Control ID: 73fdf3a0af33017dea7ad4ed22900819515980d9d1b595ded6c3b494ee218388