OL6-00-000227 - The SSH daemon must be configured to use only the SSHv2 protocol.

Information

SSH protocol version 1 suffers from design flaws that result in security vulnerabilities and should not be used.

Solution

Only SSH protocol version 2 connections should be permitted. The default setting in '/etc/ssh/sshd_config' is correct, and can be verified by ensuring that the following line appears:

Protocol 2

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Oracle_Linux_6_V2R7_STIG.zip

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-5(1)(c), CAT|I, CCI|CCI-000197, Rule-ID|SV-219560r793817_rule, STIG-ID|OL6-00-000227, STIG-Legacy|SV-64779, STIG-Legacy|V-50573, Vuln-ID|V-219560

Plugin: Unix

Control ID: f21852c9c60219ba007eff4c7d3e32af778de620a0ab1ad3e640adc52d8ac79d