GEN005506 M6 - The SSH daemon must be configured to not use CBC ciphers - 'CIPHERS does not include -CBC'

Information

The Cipher-Block Chaining (CBC) mode of encryption as implemented in the SSHv2 protocol is vulnerable to chosen plaintext attacks and must not be used.

Solution

Open a terminal session and edit the SSH daemon configuration file '/etc/sshd_config' and remove any ciphers ending with 'CBC'. If necessary, add a Ciphers line.

See Also

http://iase.disa.mil/stigs/os/mac/u_mac_osx_10.6_v1r3_stig_20130426.zip

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-13, CAT|II, CCI|CCI-000366, Rule-ID|SV-39364r1_rule, STIG-ID|GEN005506-M6, Vuln-ID|V-22459

Plugin: Unix

Control ID: fd377d5754e0b4eb64c0de090fb0cf9242c1226aba270d8ba1486692d1496cd5