GEN005510 M6 - The SSH client must be configured to only use FIPS 140-2 approved ciphers - 'CIPHERS configured'

Information

DoD information systems are required to use FIPS 140-2 approved ciphers. SSHv2 ciphers meeting this requirement are 3DES and AES.

Solution

Open a terminal session and edit the SSH client configuration file '/etc/ssh_config' and remove any ciphers not starting with '3DES' or 'AES'.

See Also

http://iase.disa.mil/stigs/os/mac/u_mac_osx_10.6_v1r3_stig_20130426.zip

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-13, CAT|II, CCI|CCI-000068, Rule-ID|SV-39371r1_rule, STIG-ID|GEN005510-M6, Vuln-ID|V-22461

Plugin: Unix

Control ID: 39085552839b0de30a768eb4684d8d1aee3b30cfa596093462c7cc9808b94107