6.2.1 Set SSH Protocol to 2

Information

SSH supports two different and incompatible protocols: SSH1 and SSH2. SSH1 was the original protocol and was subject to security issues. SSH2 is more advanced and secure.

Rationale:

SSH v1 suffers from insecurities that do not affect SSH v2.

Solution

Edit the /etc/ssh/sshd_config file to set the parameter as follows:

Protocol 2

Default Value:

OS Default: Yes

See Also

https://workbench.cisecurity.org/files/3096

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-4, CSCv7|9.2

Plugin: Unix

Control ID: bad7c5267130a491b996477235bf05d619e69bfcbcbfb2d99f9d0ae1dc9c53d0