2.6.3 Remove cryptographically weak algorithms

Information

Outdated and insecure ciphers and algorithms should not be used.

An attacker can possibly break the encryption of transported data if weak ciphers and algorithms are used
to access sensitive data.

Solution

management ssh
cipher aes128-ctr aes256-ctr
key-exchange diffie-hellman-group14-sha256
mac hmac-sha2-256

Impact:

The alogithms used in an ssh session are negotiated between the client and the server. Restricting the list of accepted algorithms could prevent some clients connecting to the device.

See Also

https://workbench.cisecurity.org/benchmarks/25683

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-13

Plugin: Arista

Control ID: b4f608f93ce0946f4820a23f8817c623601666df07d06d20d0ddb708d097e12c