UCF STIG Viewer Logo
Changes are coming to https://stigviewer.com. Take our survey to help us understand your usage and how we can better serve you in the future.
Take Survey

The SSH daemon must use a FIPS 140-2 validated cryptographic module (operating in FIPS mode).


Overview

Finding ID Version Rule ID IA Controls Severity
V-23826 GEN005490 SV-38895r1_rule DCNR-1 Medium
Description
Cryptographic modules used by the system must be validated by the NIST CVMP as compliant with FIPS 140-2. Cryptography performed by unvalidated modules is viewed by NIST as providing no protection for the data.
STIG Date
Draft AIX Security Technical Implementation Guide 2011-08-17

Details

Check Text ( C-37891r1_chk )
NOTE: This will virtually always require a manual review. Determine if the SSH daemon uses a FIPS 140-2 validated cryptographic module (operating in FIPS mode). The NIST CVMP web site provides a list of validated modules and the required security policies for the compliant use of such modules. Verify the module is on the NIST list and configured in accordance with the validated security policy. If it does not, this is a finding.
Fix Text (F-33145r1_fix)
Configure the SSH daemon to use a FIPS 140-2 validated cryptographic module (operating in FIPS mode).