Skip to content
ATO Pathways
Log In
Overview
Search
Catalogs
SCAP
OSCAL
Catalogs
Profiles
Resources
Documents
Publishers
References
Knowledge Base
Platform Documentation
Compliance Dictionary
Platform Changelog
About
Catalogs
XCCDF
Guide to the Secure Configuration of Ubuntu 20.04
Services
SSH Server
Configure OpenSSH Server if Necessary
Use Only FIPS 140-2 Validated Ciphers
Use Only FIPS 140-2 Validated Ciphers
An XCCDF Rule
Details
Profiles
Prose
Use Only FIPS 140-2 Validated Ciphers
Medium Severity
Limit the ciphers to those algorithms which are FIPS-approved. The following line in
/etc/ssh/sshd_config
demonstrates use of FIPS-approved ciphers:
Ciphers
If this line does not contain these ciphers in exact order, is commented out, or is missing, this is a finding.