GEN005505 M6 - The SSH daemon must be configured to only use FIPS 140-2 approved ciphers - 'CIPHERS configured'

Information

DoD information systems are required to use FIPS 140-2 approved ciphers. SSHv2 ciphers meeting this requirement are 3DES and AES.

Solution

Open a terminal session and edit the SSH daemon configuration file '/etc/sshd_config' to remove any ciphers not starting with '3DES' or 'AES'.

See Also

http://iase.disa.mil/stigs/os/mac/u_mac_osx_10.6_v1r3_stig_20130426.zip

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-13, CAT|II, CCI|CCI-000068, Rule-ID|SV-39360r1_rule, STIG-ID|GEN005505-M6, Vuln-ID|V-22458

Plugin: Unix

Control ID: ab9c0f3a468ca0a7e04d7a2be8ed043664c8681539171ba117a986bc4284b050