Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-66529 | JUSX-DM-000147 | SV-81019r1_rule | Medium |
Description |
---|
To protect the integrity of nonlocal maintenance sessions, SSHv2 with MAC algorithms for integrity checking must be configured. Nonlocal maintenance and diagnostic activities are those activities conducted by individuals communicating through a network, either an external network (e.g., the Internet) or an internal network. The SSHv2 protocol suite includes Layer 7 protocols such as SCP and SFTP which can be used for secure file transfers. |
STIG | Date |
---|---|
Juniper SRX SG NDM Security Technical Implementation Guide | 2019-06-28 |
Check Text ( C-67175r1_chk ) |
---|
Verify SSHv2 and MAC algorithms for integrity checking. [edit] show system services ssh If SSHv2 and integrity options are not configured in compliance with DoD requirements, this is a finding. |
Fix Text (F-72605r1_fix) |
---|
Configure SSH integrity options to comply with DoD requirements. [edit] set system services ssh protocol-version v2 set system services ssh macs hmac-sha2-512 set system services ssh macs hmac-sha2-256 set system services ssh macs hmac-sha1 set system services ssh macs hmac-sha1-96 |