GEN005510 - The SSH client must be configured to only use FIPS 140-2 approved ciphers.

Information

DoD information systems are required to use FIPS 140-2 approved ciphers. SSHv2 ciphers meeting this requirement are 3DES and AES.

Solution

Edit the SSH client configuration and remove any ciphers not starting with '3des' or 'aes' and remove any ciphers ending with 'cbc'. If necessary, add a 'Ciphers' line.

See Also

http://iasecontent.disa.mil/stigs/zip/U_RedHat_5_V1R18_STIG.zip

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-17(2), CAT|II, CCI|CCI-000068, Group-ID|V-22461, Rule-ID|SV-37828r1_rule, STIG-ID|GEN005510, Vuln-ID|V-22461

Plugin: Unix

Control ID: a3212f71b12d01070a8eef0a2af63981d4f7c4b7bb7b65bbb63992ecf9ad51fe