Skip to content

RHEL 9 draft STIG CCE-87332-3 & CCE-87567-4 #10164

@onceanddone

Description

@onceanddone

Configure SSH Server to Use FIPS 140-2 Validated Ciphers: opensshserver.config
Check is currently looking for "-oCiphers=aes256-ctr,aes192-ctr,aes128-ctr" but the files in /etc/crypto-policies/back-ends/ have changed to read "Ciphers aes256-ctr,aes192-ctr,aes128-ctr"

Configure SSH Server to Use FIPS 140-2 Validated MACs: opensshserver.config
This applies also to CCE-87567-4 which is looking for -oMACS=hmac-sha2-512,hmac-sha2-256 but should be looking for "MACS hmac-sha2-512,hmac-sha2-256"

Metadata

Metadata

Labels

RHEL9Red Hat Enterprise Linux 9 product related.STIGSTIG Benchmark related.

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions