From 8125350bad65ec28b70564f23c3023efe230d63b Mon Sep 17 00:00:00 2001 From: Arun Sharma Date: Wed, 7 Oct 2026 00:16:54 +0530 Subject: [PATCH] Revert "[rc-4.10] PE-9697: stop kairos-init overriding the FIPS/STIG sshd crypto (#901)" This reverts commit 789ae7124ddabdbdf62ea7b05d1f1377e33ddd40. Removes 04_stig_hardening.conf and 04_fips_hardening.conf and restores 100_stig_crypto.conf and 100_fips_crypto.conf to their previous contents. --- .../etc/ssh/sshd_config.d/04_fips_hardening.conf | 13 ------------- .../etc/ssh/sshd_config.d/100_fips_crypto.conf | 6 ++++++ .../etc/ssh/sshd_config.d/04_fips_hardening.conf | 13 ------------- .../etc/ssh/sshd_config.d/100_fips_crypto.conf | 6 ++++++ .../etc/ssh/sshd_config.d/04_stig_hardening.conf | 13 ------------- .../etc/ssh/sshd_config.d/100_stig_crypto.conf | 14 ++++++++++++++ 6 files changed, 26 insertions(+), 39 deletions(-) delete mode 100644 rhel-fips/overlay/rhel10/etc/ssh/sshd_config.d/04_fips_hardening.conf create mode 100644 rhel-fips/overlay/rhel10/etc/ssh/sshd_config.d/100_fips_crypto.conf delete mode 100644 rhel-fips/overlay/rhel9/etc/ssh/sshd_config.d/04_fips_hardening.conf create mode 100644 rhel-fips/overlay/rhel9/etc/ssh/sshd_config.d/100_fips_crypto.conf delete mode 100644 rhel-stig/overlay/rhel9/etc/ssh/sshd_config.d/04_stig_hardening.conf create mode 100644 rhel-stig/overlay/rhel9/etc/ssh/sshd_config.d/100_stig_crypto.conf diff --git a/rhel-fips/overlay/rhel10/etc/ssh/sshd_config.d/04_fips_hardening.conf b/rhel-fips/overlay/rhel10/etc/ssh/sshd_config.d/04_fips_hardening.conf deleted file mode 100644 index eab4c1eb..00000000 --- a/rhel-fips/overlay/rhel10/etc/ssh/sshd_config.d/04_fips_hardening.conf +++ /dev/null @@ -1,13 +0,0 @@ -# Must sort before kairos-init's 05-kairos-hardening.conf: sshd keeps the first -# value it reads for each directive, and reads this directory in lexical order. -# -# Plain replacement lists, not '^'. '^' prepends to the defaults, which leaves -# the non-FIPS algorithms on offer for a peer to negotiate. -Ciphers aes256-gcm@openssh.com,aes128-gcm@openssh.com,aes256-ctr,aes128-ctr -KexAlgorithms ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256 -MACs hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-512 -HostKeyAlgorithms ecdsa-sha2-nistp256,ecdsa-sha2-nistp384,ecdsa-sha2-nistp521,rsa-sha2-256,rsa-sha2-512 - -# kairos-init sets 2; a client carrying agent keys is disconnected before the -# password prompt. 4 is within the STIG and CIS limits. -MaxAuthTries 4 diff --git a/rhel-fips/overlay/rhel10/etc/ssh/sshd_config.d/100_fips_crypto.conf b/rhel-fips/overlay/rhel10/etc/ssh/sshd_config.d/100_fips_crypto.conf new file mode 100644 index 00000000..717dc6dd --- /dev/null +++ b/rhel-fips/overlay/rhel10/etc/ssh/sshd_config.d/100_fips_crypto.conf @@ -0,0 +1,6 @@ +# Default algorithms favoring higher-performance FIPS algorithms +# in most cases. +Ciphers ^aes256-gcm@openssh.com,aes256-ctr,aes128-gcm@openssh.com,aes128-ctr +KexAlgorithms ^ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521 +MACs ^hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-512 +HostKeyAlgorithms ^ecdsa-sha2-nistp256,ecdsa-sha2-nistp384,ecdsa-sha2-nistp521,rsa-sha2-256,rsa-sha2-512 \ No newline at end of file diff --git a/rhel-fips/overlay/rhel9/etc/ssh/sshd_config.d/04_fips_hardening.conf b/rhel-fips/overlay/rhel9/etc/ssh/sshd_config.d/04_fips_hardening.conf deleted file mode 100644 index eab4c1eb..00000000 --- a/rhel-fips/overlay/rhel9/etc/ssh/sshd_config.d/04_fips_hardening.conf +++ /dev/null @@ -1,13 +0,0 @@ -# Must sort before kairos-init's 05-kairos-hardening.conf: sshd keeps the first -# value it reads for each directive, and reads this directory in lexical order. -# -# Plain replacement lists, not '^'. '^' prepends to the defaults, which leaves -# the non-FIPS algorithms on offer for a peer to negotiate. -Ciphers aes256-gcm@openssh.com,aes128-gcm@openssh.com,aes256-ctr,aes128-ctr -KexAlgorithms ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256 -MACs hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-512 -HostKeyAlgorithms ecdsa-sha2-nistp256,ecdsa-sha2-nistp384,ecdsa-sha2-nistp521,rsa-sha2-256,rsa-sha2-512 - -# kairos-init sets 2; a client carrying agent keys is disconnected before the -# password prompt. 4 is within the STIG and CIS limits. -MaxAuthTries 4 diff --git a/rhel-fips/overlay/rhel9/etc/ssh/sshd_config.d/100_fips_crypto.conf b/rhel-fips/overlay/rhel9/etc/ssh/sshd_config.d/100_fips_crypto.conf new file mode 100644 index 00000000..717dc6dd --- /dev/null +++ b/rhel-fips/overlay/rhel9/etc/ssh/sshd_config.d/100_fips_crypto.conf @@ -0,0 +1,6 @@ +# Default algorithms favoring higher-performance FIPS algorithms +# in most cases. +Ciphers ^aes256-gcm@openssh.com,aes256-ctr,aes128-gcm@openssh.com,aes128-ctr +KexAlgorithms ^ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521 +MACs ^hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-512 +HostKeyAlgorithms ^ecdsa-sha2-nistp256,ecdsa-sha2-nistp384,ecdsa-sha2-nistp521,rsa-sha2-256,rsa-sha2-512 \ No newline at end of file diff --git a/rhel-stig/overlay/rhel9/etc/ssh/sshd_config.d/04_stig_hardening.conf b/rhel-stig/overlay/rhel9/etc/ssh/sshd_config.d/04_stig_hardening.conf deleted file mode 100644 index eab4c1eb..00000000 --- a/rhel-stig/overlay/rhel9/etc/ssh/sshd_config.d/04_stig_hardening.conf +++ /dev/null @@ -1,13 +0,0 @@ -# Must sort before kairos-init's 05-kairos-hardening.conf: sshd keeps the first -# value it reads for each directive, and reads this directory in lexical order. -# -# Plain replacement lists, not '^'. '^' prepends to the defaults, which leaves -# the non-FIPS algorithms on offer for a peer to negotiate. -Ciphers aes256-gcm@openssh.com,aes128-gcm@openssh.com,aes256-ctr,aes128-ctr -KexAlgorithms ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256 -MACs hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-512 -HostKeyAlgorithms ecdsa-sha2-nistp256,ecdsa-sha2-nistp384,ecdsa-sha2-nistp521,rsa-sha2-256,rsa-sha2-512 - -# kairos-init sets 2; a client carrying agent keys is disconnected before the -# password prompt. 4 is within the STIG and CIS limits. -MaxAuthTries 4 diff --git a/rhel-stig/overlay/rhel9/etc/ssh/sshd_config.d/100_stig_crypto.conf b/rhel-stig/overlay/rhel9/etc/ssh/sshd_config.d/100_stig_crypto.conf new file mode 100644 index 00000000..587e391e --- /dev/null +++ b/rhel-stig/overlay/rhel9/etc/ssh/sshd_config.d/100_stig_crypto.conf @@ -0,0 +1,14 @@ +# STIG-compliant SSH cryptographic settings for RHEL 9 +# These settings align with DISA STIG requirements + +# Approved ciphers (STIG compliant) +Ciphers aes256-gcm@openssh.com,aes128-gcm@openssh.com,aes256-ctr,aes128-ctr + +# Approved key exchange algorithms (STIG compliant) +KexAlgorithms ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256 + +# Approved MAC algorithms (STIG compliant) +MACs hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-512 + +# Approved host key algorithms (STIG compliant) +HostKeyAlgorithms ecdsa-sha2-nistp256,ecdsa-sha2-nistp384,ecdsa-sha2-nistp521,rsa-sha2-256,rsa-sha2-512