CCI|CCI-000877

Title

Employ strong authentication in the establishment of nonlocal maintenance and diagnostic sessions.

Reference Item Details

Category: 2024

Audit Items

View all Reference Audit Items

NamePluginAudit Name
1.4 OL08-00-010020UnixCIS Oracle Linux 8 STIG v1.0.0 CAT I
1.40 OL08-00-010290UnixCIS Oracle Linux 8 STIG v1.0.0 CAT II
1.41 OL08-00-010291UnixCIS Oracle Linux 8 STIG v1.0.0 CAT II
1.59 APPL-14-001150UnixCIS Apple macOS 14 (Sonoma) STIG v1.0.0 CAT I
1.66 UBTU-22-255065UnixCIS Ubuntu Linux 22.04 LTS STIG v1.0.0 CAT II
1.98 UBTU-24-500050UnixCIS Ubuntu Linux 24.04 LTS STIG v1.0.0 CAT II
1.142 WN22-CC-000490WindowsCIS Microsoft Windows Server 2022 STIG v3.0.0 MS CAT II
1.142 WN22-CC-000490WindowsCIS Microsoft Windows Server 2022 STIG v3.0.0 DC CAT II
1.170 WN10-CC-000330WindowsCIS Microsoft Windows 10 STIG v1.0.0 CAT I
1.172 WN10-CC-000345WindowsCIS Microsoft Windows 10 STIG v1.0.0 CAT I
1.175 WN10-CC-000360WindowsCIS Microsoft Windows 10 STIG v1.0.0 CAT II
1.211 RHEL-09-255050UnixCIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT I
1.446 RHEL-09-671010UnixCIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT I
5.1.6 Ensure sshd Ciphers are configuredUnixCIS Rocky Linux 10 v1.0.0 L1 Server
5.1.6 Ensure sshd Ciphers are configuredUnixCIS Rocky Linux 10 v1.0.0 L1 Workstation
5.1.15 Ensure sshd MACs are configuredUnixCIS Rocky Linux 10 v1.0.0 L1 Workstation
5.1.15 Ensure sshd MACs are configuredUnixCIS Rocky Linux 10 v1.0.0 L1 Server
AIX7-00-001102 - AIX must employ strong authenticators in the establishment of nonlocal maintenance and diagnostic sessions.UnixDISA STIG AIX 7.x v3r1
ALMA-09-004310 - AlmaLinux OS 9 must use the TuxCare ESU repository.UnixDISA Cloud Linux AlmaLinux OS 9 STIG v1r5
ALMA-09-004320 - AlmaLinux OS 9 must use the TuxCare FIPS packages and not the default encryption packages.UnixDISA Cloud Linux AlmaLinux OS 9 STIG v1r5
ALMA-09-004420 - AlmaLinux OS 9 must enable FIPS mode.UnixDISA Cloud Linux AlmaLinux OS 9 STIG v1r5
ALMA-09-040390 - AlmaLinux OS 9 must enable the Pluggable Authentication Module (PAM) interface for SSHD.UnixDISA Cloud Linux AlmaLinux OS 9 STIG v1r5
AOSX-13-000054 - The macOS system must implement approved Ciphers to protect the confidentiality of SSH connections.UnixDISA STIG Apple Mac OSX 10.13 v2r5
AOSX-13-000055 - The macOS system must use only Message Authentication Codes (MACs) employing FIPS 140-2 validated cryptographic hash algorithms.UnixDISA STIG Apple Mac OSX 10.13 v2r5
AOSX-13-000056 - The macOS system must implement an approved Key Exchange Algorithm.UnixDISA STIG Apple Mac OSX 10.13 v2r5
AOSX-13-000605 - The macOS system must not use telnet.UnixDISA STIG Apple Mac OSX 10.13 v2r5
AOSX-14-000054 - The macOS system must implement approved Ciphers to protect the confidentiality of SSH connections.UnixDISA STIG Apple Mac OSX 10.14 v2r6
AOSX-14-000055 - The macOS system must use only Message Authentication Codes (MACs) employing FIPS 140-2 validated cryptographic hash algorithms.UnixDISA STIG Apple Mac OSX 10.14 v2r6
AOSX-14-000056 - The macOS system must implement an approved Key Exchange Algorithm.UnixDISA STIG Apple Mac OSX 10.14 v2r6
AOSX-14-003024 - The macOS system must use multifactor authentication in the establishment of nonlocal maintenance and diagnostic sessions - ChallengeResponseAuthenticationUnixDISA STIG Apple Mac OSX 10.14 v2r6
AOSX-14-003024 - The macOS system must use multifactor authentication in the establishment of nonlocal maintenance and diagnostic sessions - enforceSmartCardUnixDISA STIG Apple Mac OSX 10.14 v2r6
AOSX-14-003024 - The macOS system must use multifactor authentication in the establishment of nonlocal maintenance and diagnostic sessions - PasswordAuthenticationUnixDISA STIG Apple Mac OSX 10.14 v2r6
AOSX-15-000054 - The macOS system must implement approved Ciphers to protect the confidentiality of SSH connections..UnixDISA STIG Apple Mac OSX 10.15 v1r10
AOSX-15-000055 - The macOS system must use only Message Authentication Codes (MACs) employing FIPS 140-2 validated cryptographic hash algorithms.UnixDISA STIG Apple Mac OSX 10.15 v1r10
AOSX-15-000056 - The macOS system must implement an approved Key Exchange Algorithm.UnixDISA STIG Apple Mac OSX 10.15 v1r10
APPL-12-000057 - The macOS system must implement approved ciphers within the SSH client configuration to protect the confidentiality of SSH connections.UnixDISA STIG Apple macOS 12 v1r9
APPL-12-000058 - The macOS system must implement approved Message Authentication Codes (MACs) within the SSH client configuration.UnixDISA STIG Apple macOS 12 v1r9
APPL-12-000059 - The macOS system must implement approved Key Exchange Algorithms within the SSH client configuration.UnixDISA STIG Apple macOS 12 v1r9
APPL-13-000054 - The macOS system must implement approved ciphers within the SSH server configuration to protect the confidentiality of SSH connections.UnixDISA STIG Apple macOS 13 v1r5
APPL-13-000055 - The macOS system must implement approved Message Authentication Codes (MACs) within the SSH server configuration.UnixDISA STIG Apple macOS 13 v1r5
APPL-13-000056 - The macOS system must implement approved Key Exchange Algorithms within the SSH server configuration.UnixDISA STIG Apple macOS 13 v1r5
APPL-13-000057 - The macOS system must implement approved ciphers within the SSH client configuration to protect the confidentiality of SSH connections.UnixDISA STIG Apple macOS 13 v1r5
APPL-13-000058 - The macOS system must implement approved Message Authentication Codes (MACs) within the SSH client configuration.UnixDISA STIG Apple macOS 13 v1r5
APPL-13-000059 - The macOS system must implement approved Key Exchange Algorithms within the SSH client configuration.UnixDISA STIG Apple macOS 13 v1r5
APPL-14-001150 - The macOS system must disable password authentication for SSH.UnixDISA Apple macOS 14 Sonoma STIG v2r4
APPL-15-001150 - The macOS system must disable password authentication for SSH.UnixDISA Apple macOS 15 Sequoia STIG v1r6
APPL-26-001150 - The macOS system must disable password authentication for SSH.UnixDISA Apple macOS 26 Tahoe STIG v1r1
AZLX-23-001255 - Amazon Linux 2023 must enable the Pluggable Authentication Module (PAM) interface for SSHD.UnixDISA Amazon Linux 2023 STIG v1r2
AZLX-23-001280 - Amazon Linux 2023 must enable FIPS mode.UnixDISA Amazon Linux 2023 STIG v1r2
Catalina - Enforce Smartcard AuthenticationUnixNIST macOS Catalina v1.5.0 - 800-53r4 High