CCI|CCI-001453

Title

Implement cryptographic mechanisms to protect the integrity of remote access sessions.

Reference Item Details

Category: 2024

Audit Items

View all Reference Audit Items

NamePluginAudit Name
1.4 OL08-00-010020UnixCIS Oracle Linux 8 STIG v1.0.0 CAT I
1.25 UBTU-24-100830UnixCIS Ubuntu Linux 24.04 LTS STIG v1.0.0 CAT II
1.27 UBTU-24-100850UnixCIS Ubuntu Linux 24.04 LTS STIG v1.0.0 CAT II
1.28 UBTU-24-100860UnixCIS Ubuntu Linux 24.04 LTS STIG v1.0.0 CAT II
1.39 OL08-00-010287UnixCIS Oracle Linux 8 STIG v1.0.0 CAT II
1.43 OL08-00-010293UnixCIS Oracle Linux 8 STIG v1.0.0 CAT II
1.44 OL08-00-010294UnixCIS Oracle Linux 8 STIG v1.0.0 CAT II
1.45 OL08-00-010295UnixCIS Oracle Linux 8 STIG v1.0.0 CAT II
1.64 UBTU-22-255055UnixCIS Ubuntu Linux 22.04 LTS STIG v1.0.0 CAT II
1.212 RHEL-09-255055UnixCIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT II
1.213 RHEL-09-255060UnixCIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT II
1.214 RHEL-09-255064UnixCIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT II
1.215 RHEL-09-255065UnixCIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT II
1.216 RHEL-09-255070UnixCIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT II
1.217 RHEL-09-255075UnixCIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT II
1.367 OL08-00-040342UnixCIS Oracle Linux 8 STIG v1.0.0 CAT II
2.2.26 Ensure ldap_tls_cacert is set for LDAP - configUnixCIS Red Hat Enterprise Linux 7 STIG v2.0.0 STIG
2.2.26 Ensure ldap_tls_cacert is set for LDAP - fileUnixCIS Red Hat Enterprise Linux 7 STIG v2.0.0 STIG
2.2.27 Ensure ldap_id_use_start_tls is set for LDAP - LDAP authentication communications.UnixCIS Red Hat Enterprise Linux 7 STIG v2.0.0 STIG
2.2.28 Ensure ldap_tls_reqcert is set for LDAP - LDAP communications.UnixCIS Red Hat Enterprise Linux 7 STIG v2.0.0 STIG
5.3.17 Ensure only strong MAC algorithms are used - MACs employing FIPS 140-2 approved cryptographic hash algorithms.UnixCIS Red Hat Enterprise Linux 7 STIG v2.0.0 STIG
AIX7-00-001104 - If LDAP authentication is required on AIX, SSL must be used between LDAP clients and the LDAP servers to protect the integrity of remote access sessions.UnixDISA STIG AIX 7.x v3r1
ALMA-09-002990 - AlmaLinux OS 9 SSH client must be configured to use only encryption ciphers employing FIPS 140-3 validated cryptographic hash algorithms to protect the confidentiality of SSH client connections.UnixDISA CloudLinux AlmaLinux OS 9 STIG v1r2
ALMA-09-003100 - AlmaLinux OS 9 must implement DOD-approved encryption ciphers to protect the confidentiality of SSH client connections.UnixDISA CloudLinux AlmaLinux OS 9 STIG v1r2
ALMA-09-003210 - AlmaLinux OS 9 SSH client must be configured to use only Message Authentication Codes (MACs) employing FIPS 140-3 validated cryptographic hash algorithms.UnixDISA CloudLinux AlmaLinux OS 9 STIG v1r2
ALMA-09-003320 - AlmaLinux OS 9 must implement DOD-approved encryption ciphers to protect the confidentiality of SSH server connections.UnixDISA CloudLinux AlmaLinux OS 9 STIG v1r2
ALMA-09-003325 - AlmaLinux OS 9 SSH server must be configured to use only FIPS 140-3 validated key exchange algorithms.UnixDISA CloudLinux AlmaLinux OS 9 STIG v1r2
ALMA-09-003430 - AlmaLinux OS 9 must implement DOD-approved systemwide cryptographic policies to protect the confidentiality of SSH server connections.UnixDISA CloudLinux AlmaLinux OS 9 STIG v1r2
ALMA-09-003540 - AlmaLinux OS 9 SSH server must be configured to use only Message Authentication Codes (MACs) employing FIPS 140-3 validated cryptographic hash algorithms.UnixDISA CloudLinux AlmaLinux OS 9 STIG v1r2
ALMA-09-003760 - AlmaLinux OS 9 must implement DOD-approved TLS encryption in the GnuTLS package.UnixDISA CloudLinux AlmaLinux OS 9 STIG v1r2
ALMA-09-003980 - AlmaLinux OS 9 must implement DOD-approved encryption in the OpenSSL package.UnixDISA CloudLinux AlmaLinux OS 9 STIG v1r2
ALMA-09-004090 - AlmaLinux OS 9 must implement DOD-approved TLS encryption in the OpenSSL package.UnixDISA CloudLinux AlmaLinux OS 9 STIG v1r2
AOSX-13-000605 - The macOS system must not use telnet.UnixDISA STIG Apple Mac OSX 10.13 v2r5
AOSX-14-000011 - The macOS system must implement DoD-approved encryption to protect the confidentiality and integrity of remote access sessions including transmitted data and data during preparation for transmission - OpenSSH versionUnixDISA STIG Apple Mac OSX 10.14 v2r6
AOSX-14-000011 - The macOS system must implement DoD-approved encryption to protect the confidentiality and integrity of remote access sessions including transmitted data and data during preparation for transmission - SSHD currently runningUnixDISA STIG Apple Mac OSX 10.14 v2r6
AOSX-14-000011 - The macOS system must implement DoD-approved encryption to protect the confidentiality and integrity of remote access sessions including transmitted data and data during preparation for transmission - SSHD service disabledUnixDISA STIG Apple Mac OSX 10.14 v2r6
APPL-11-000011 - The macOS system must disable the SSHD service.UnixDISA STIG Apple macOS 11 v1r8
APPL-11-000011 - The macOS system must disable the SSHD service.UnixDISA STIG Apple macOS 11 v1r5
APPL-12-000057 - The macOS system must implement approved ciphers within the SSH client configuration to protect the confidentiality of SSH connections.UnixDISA STIG Apple macOS 12 v1r9
APPL-12-000058 - The macOS system must implement approved Message Authentication Codes (MACs) within the SSH client configuration.UnixDISA STIG Apple macOS 12 v1r9
APPL-12-000059 - The macOS system must implement approved Key Exchange Algorithms within the SSH client configuration.UnixDISA STIG Apple macOS 12 v1r9
APPL-13-000054 - The macOS system must implement approved ciphers within the SSH server configuration to protect the confidentiality of SSH connections.UnixDISA STIG Apple macOS 13 v1r5
APPL-13-000055 - The macOS system must implement approved Message Authentication Codes (MACs) within the SSH server configuration.UnixDISA STIG Apple macOS 13 v1r5
APPL-13-000056 - The macOS system must implement approved Key Exchange Algorithms within the SSH server configuration.UnixDISA STIG Apple macOS 13 v1r5
APPL-13-000057 - The macOS system must implement approved ciphers within the SSH client configuration to protect the confidentiality of SSH connections.UnixDISA STIG Apple macOS 13 v1r5
APPL-13-000058 - The macOS system must implement approved Message Authentication Codes (MACs) within the SSH client configuration.UnixDISA STIG Apple macOS 13 v1r5
APPL-13-000059 - The macOS system must implement approved Key Exchange Algorithms within the SSH client configuration.UnixDISA STIG Apple macOS 13 v1r5
APPL-14-000054 The macOS system must limit SSHD to FIPS-compliant connections.UnixDISA Apple macOS 14 (Sonoma) STIG v2r3
APPL-14-000057 The macOS system must limit SSH to FIPS-compliant connections.UnixDISA Apple macOS 14 (Sonoma) STIG v2r3
APPL-15-000054 - The macOS system must limit SSHD to FIPS-compliant connections.UnixDISA Apple macOS 15 (Sequoia) STIG v1r4