diff --git a/rhel-fips/overlay/rhel10/etc/ssh/sshd_config.d/04_fips_hardening.conf b/rhel-fips/overlay/rhel10/etc/ssh/sshd_config.d/04_fips_hardening.conf deleted file mode 100644 index eab4c1eb..00000000 --- a/rhel-fips/overlay/rhel10/etc/ssh/sshd_config.d/04_fips_hardening.conf +++ /dev/null @@ -1,13 +0,0 @@ -# Must sort before kairos-init's 05-kairos-hardening.conf: sshd keeps the first -# value it reads for each directive, and reads this directory in lexical order. -# -# Plain replacement lists, not '^'. '^' prepends to the defaults, which leaves -# the non-FIPS algorithms on offer for a peer to negotiate. -Ciphers aes256-gcm@openssh.com,aes128-gcm@openssh.com,aes256-ctr,aes128-ctr -KexAlgorithms ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256 -MACs hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-512 -HostKeyAlgorithms ecdsa-sha2-nistp256,ecdsa-sha2-nistp384,ecdsa-sha2-nistp521,rsa-sha2-256,rsa-sha2-512 - -# kairos-init sets 2; a client carrying agent keys is disconnected before the -# password prompt. 4 is within the STIG and CIS limits. -MaxAuthTries 4 diff --git a/rhel-fips/overlay/rhel10/etc/ssh/sshd_config.d/100_fips_crypto.conf b/rhel-fips/overlay/rhel10/etc/ssh/sshd_config.d/100_fips_crypto.conf new file mode 100644 index 00000000..717dc6dd --- /dev/null +++ b/rhel-fips/overlay/rhel10/etc/ssh/sshd_config.d/100_fips_crypto.conf @@ -0,0 +1,6 @@ +# Default algorithms favoring higher-performance FIPS algorithms +# in most cases. +Ciphers ^aes256-gcm@openssh.com,aes256-ctr,aes128-gcm@openssh.com,aes128-ctr +KexAlgorithms ^ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521 +MACs ^hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-512 +HostKeyAlgorithms ^ecdsa-sha2-nistp256,ecdsa-sha2-nistp384,ecdsa-sha2-nistp521,rsa-sha2-256,rsa-sha2-512 \ No newline at end of file diff --git a/rhel-fips/overlay/rhel9/etc/ssh/sshd_config.d/04_fips_hardening.conf b/rhel-fips/overlay/rhel9/etc/ssh/sshd_config.d/04_fips_hardening.conf deleted file mode 100644 index eab4c1eb..00000000 --- a/rhel-fips/overlay/rhel9/etc/ssh/sshd_config.d/04_fips_hardening.conf +++ /dev/null @@ -1,13 +0,0 @@ -# Must sort before kairos-init's 05-kairos-hardening.conf: sshd keeps the first -# value it reads for each directive, and reads this directory in lexical order. -# -# Plain replacement lists, not '^'. '^' prepends to the defaults, which leaves -# the non-FIPS algorithms on offer for a peer to negotiate. -Ciphers aes256-gcm@openssh.com,aes128-gcm@openssh.com,aes256-ctr,aes128-ctr -KexAlgorithms ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256 -MACs hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-512 -HostKeyAlgorithms ecdsa-sha2-nistp256,ecdsa-sha2-nistp384,ecdsa-sha2-nistp521,rsa-sha2-256,rsa-sha2-512 - -# kairos-init sets 2; a client carrying agent keys is disconnected before the -# password prompt. 4 is within the STIG and CIS limits. -MaxAuthTries 4 diff --git a/rhel-fips/overlay/rhel9/etc/ssh/sshd_config.d/100_fips_crypto.conf b/rhel-fips/overlay/rhel9/etc/ssh/sshd_config.d/100_fips_crypto.conf new file mode 100644 index 00000000..717dc6dd --- /dev/null +++ b/rhel-fips/overlay/rhel9/etc/ssh/sshd_config.d/100_fips_crypto.conf @@ -0,0 +1,6 @@ +# Default algorithms favoring higher-performance FIPS algorithms +# in most cases. +Ciphers ^aes256-gcm@openssh.com,aes256-ctr,aes128-gcm@openssh.com,aes128-ctr +KexAlgorithms ^ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521 +MACs ^hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-512 +HostKeyAlgorithms ^ecdsa-sha2-nistp256,ecdsa-sha2-nistp384,ecdsa-sha2-nistp521,rsa-sha2-256,rsa-sha2-512 \ No newline at end of file diff --git a/rhel-stig/overlay/rhel9/etc/ssh/sshd_config.d/04_stig_hardening.conf b/rhel-stig/overlay/rhel9/etc/ssh/sshd_config.d/04_stig_hardening.conf deleted file mode 100644 index eab4c1eb..00000000 --- a/rhel-stig/overlay/rhel9/etc/ssh/sshd_config.d/04_stig_hardening.conf +++ /dev/null @@ -1,13 +0,0 @@ -# Must sort before kairos-init's 05-kairos-hardening.conf: sshd keeps the first -# value it reads for each directive, and reads this directory in lexical order. -# -# Plain replacement lists, not '^'. '^' prepends to the defaults, which leaves -# the non-FIPS algorithms on offer for a peer to negotiate. -Ciphers aes256-gcm@openssh.com,aes128-gcm@openssh.com,aes256-ctr,aes128-ctr -KexAlgorithms ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256 -MACs hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-512 -HostKeyAlgorithms ecdsa-sha2-nistp256,ecdsa-sha2-nistp384,ecdsa-sha2-nistp521,rsa-sha2-256,rsa-sha2-512 - -# kairos-init sets 2; a client carrying agent keys is disconnected before the -# password prompt. 4 is within the STIG and CIS limits. -MaxAuthTries 4 diff --git a/rhel-stig/overlay/rhel9/etc/ssh/sshd_config.d/100_stig_crypto.conf b/rhel-stig/overlay/rhel9/etc/ssh/sshd_config.d/100_stig_crypto.conf new file mode 100644 index 00000000..587e391e --- /dev/null +++ b/rhel-stig/overlay/rhel9/etc/ssh/sshd_config.d/100_stig_crypto.conf @@ -0,0 +1,14 @@ +# STIG-compliant SSH cryptographic settings for RHEL 9 +# These settings align with DISA STIG requirements + +# Approved ciphers (STIG compliant) +Ciphers aes256-gcm@openssh.com,aes128-gcm@openssh.com,aes256-ctr,aes128-ctr + +# Approved key exchange algorithms (STIG compliant) +KexAlgorithms ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256 + +# Approved MAC algorithms (STIG compliant) +MACs hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-512 + +# Approved host key algorithms (STIG compliant) +HostKeyAlgorithms ecdsa-sha2-nistp256,ecdsa-sha2-nistp384,ecdsa-sha2-nistp521,rsa-sha2-256,rsa-sha2-512