GEN005511 - The SSH client must be configured to not use CBC-based ciphers.

Information

The (CBC) mode of encryption as implemented in the SSHv2 protocol is vulnerable to chosen-plaintext attacks and must not be used.

Solution

Edit the SSH client configuration and remove any ciphers not starting with '3des' or 'aes' and remove any ciphers ending with 'cbc'. If necessary, add a 'Ciphers' line.

See Also

http://iasecontent.disa.mil/stigs/zip/U_RedHat_5_V1R17_STIG.zip

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-13, CAT|II, CCI|CCI-000366, Group-ID|V-22462, Rule-ID|SV-37830r1_rule, STIG-ID|GEN005511

Plugin: Unix

Control ID: b1966388dfe2637f6f6fa066133ea3478d5556624bed7b831617bc1d256d48f5