5.1.7 Ensure sshd Ciphers are configured

Information

Secure Shell (SSH) ciphers are encryption algorithms used by the SSH protocol to secure data transmitted between a client and a server. They protect the privacy and integrity of the connection, using symmetric encryption to encrypt data after a secure session is established. During connection setup, the client and server negotiate to select the strongest available cipher that both support, ensuring the connection is as secure as possible

More information about the openSSH server configuration is available in the "Configure SSH Server" section overview.

Weak ciphers that are used for authentication to the cryptographic module cannot be relied upon to provide confidentiality or integrity, and system data may be compromised.

Solution

Edit or create a drop-in file under /etc/ssh/sshd_config.d/ to remove weak ciphers using the subtractive form. The drop-in file should be named so that lexical order places it before any other drop-in that sets Ciphers :

Ciphers -3des-cbc,blowfish-cbc,cast128-cbc,aes128-cbc,aes192-cbc,aes256-cbc,arcfour,arcfour128,arcfour256,[email protected]

Example 10-cis-sshd.conf :

# printf '%s\n' 'Ciphers -3des-cbc,blowfish-cbc,cast128-cbc,aes128-cbc,aes192-cbc,aes256-cbc,arcfour,arcfour128,arcfour256,[email protected]' >> /etc/ssh/sshd_config.d/10-cis-sshd.conf

Apply the change to the running daemon:

# systemctl reload-or-restart sshd.service

Note:

- The list above contains the cipher algorithms that this recommendation prohibits. If the site has additional ciphers it wishes to disable (e.g., to align with a site-specific crypto policy), append them to the Ciphers - argument, comma-separated, with no spaces. The subtractive form removes the listed algorithms from OpenSSH's compiled-in default set, so future additions to that default set are inherited rather than frozen.
- Verify the effective post-include configuration with sshd -T | grep -i ciphers . The sshd -T output is the authoritative source for what the running daemon will negotiate.

Impact:

A too restrictive list of ciphers can lead to the "no matching cipher found" error during an SSH connection. This error indicates that the SSH client and server are unable to agree on a common cipher to use for the secure communication. This typically occurs due to a mismatch in supported ciphers or when older, less secure ciphers are disabled on one side but still expected by the other.

See Also

https://workbench.cisecurity.org/benchmarks/27798

Item Details

Category: ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|AC-17(2), 800-53|IA-5, 800-53|IA-5(1), 800-53|SC-8, 800-53|SC-8(1), CSCv7|14.4

Plugin: Unix

Control ID: 89983146810885d6b4061903ed6d467313e011e86cf08e3c5930cc1badfa53bf