# STIG- Configure SSH Client to Use FIPS 140-2 Validated Ciphers: openssh.config

**URL:** <https://forums.rockylinux.org/t/stig-configure-ssh-client-to-use-fips-140-2-validated-ciphers-openssh-config/13187>\
**Category:** Rocky Linux Help & Support\
**Created:** [March 13, 2024, 4:32am UTC](https://forums.rockylinux.org/t/stig-configure-ssh-client-to-use-fips-140-2-validated-ciphers-openssh-config/13187 "2024-03-13T04:32:32Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![sagarseapatil](https://avatars.discourse-cdn.com/v4/letter/s/ebca7d/32.png) [@sagarseapatil](https://forums.rockylinux.org/u/sagarseapatil)\
**Post date:** [March 13, 2024, 4:32am UTC](https://forums.rockylinux.org/t/stig-configure-ssh-client-to-use-fips-140-2-validated-ciphers-openssh-config/13187/1 "2024-03-13T04:32:32Z")

</div>

We use STIG in FEDRAMP and we see this control fail w.r.t FIPS 140-2

Crypto Policies provide a centralized control over crypto algorithms usage of many packages. OpenSSH is supported by system crypto policy, but the OpenSSH configuration may be set up incorrectly. To check that Crypto Policies settings for ciphers are configured correctly, ensure that /etc/crypto-policies/back-ends/openssh.config contains the following line and is not commented out:

Ciphers [aes256-ctr,aes192-ctr,aes128-ctr,aes256-gcm@openssh.com](mailto:aes256-ctr,aes192-ctr,aes128-ctr,aes256-gcm@openssh.com),aes128-gcm@openssh.com

Since Rocky Linux 8 is FIPS 140-3 complaint , will it fall in false positive .?

Can we ignore this control?

---

<div class="post-metadata">

**Author:** ![linde](https://avatars.discourse-cdn.com/v4/letter/l/e36b37/32.png) [@linde](https://forums.rockylinux.org/u/linde)\
**Post date:** [March 13, 2024, 4:55pm UTC](https://forums.rockylinux.org/t/stig-configure-ssh-client-to-use-fips-140-2-validated-ciphers-openssh-config/13187/2 "2024-03-13T16:55:44Z")

</div>

> Can we ignore this control?

Not if I understand anything about FedRAMP or government-mandated security controls in general. (Disclaimer: I’ve never done any of these regulated environments myself, so everything I “know” is either second-hand or half remembered from documentation.)

Unless your system was configured with a FIPS-compatible security profile from the beginning, or explicitly set into one, you’re probably not compliant. `man crypto-policies` and `man fips-mode-setup` should point you in the right direction.

---

<div class="post-metadata">

**Author:** ![sagarseapatil](https://avatars.discourse-cdn.com/v4/letter/s/ebca7d/32.png) [@sagarseapatil](https://forums.rockylinux.org/u/sagarseapatil)\
**Post date:** [March 13, 2024, 6:13pm UTC](https://forums.rockylinux.org/t/stig-configure-ssh-client-to-use-fips-140-2-validated-ciphers-openssh-config/13187/3 "2024-03-13T18:13:34Z")

</div>

We have enabled Fips successful in our systems  
fips-mode-setup --check  
FIPS mode is enabled

RockyLinux lacks a STIG profile, hence the report uses the Redhat-8 profile instead.  
Additionally, several controls fail in relation to FIPS 140-2, although Rocky Linux 8 complies with FIPS 140-3.  
So do we apply these controls or treat them as false positives.

---

<div class="post-metadata">

**Author:** ![LinuxGuy1997](https://avatars.discourse-cdn.com/v4/letter/l/d26b3c/32.png) [@LinuxGuy1997](https://forums.rockylinux.org/u/LinuxGuy1997)\
**Post date:** [March 13, 2024, 7:45pm UTC](https://forums.rockylinux.org/t/stig-configure-ssh-client-to-use-fips-140-2-validated-ciphers-openssh-config/13187/4 "2024-03-13T19:45:22Z")

</div>

Well [FIPS 140-3 supersedes FIPS 140-2](https://csrc.nist.gov/projects/fips-140-3-transition-effort)… exactly how that applies to your specific security case, I don’t know. Who in your organization is setting the standards, verifying compliance, etc.?

---

<div class="post-metadata">

**Author:** ![label](https://avatars.discourse-cdn.com/v4/letter/l/c5a1d2/32.png) [@label](https://forums.rockylinux.org/u/label)\
**Post date:** [March 14, 2024, 12:17am UTC](https://forums.rockylinux.org/t/stig-configure-ssh-client-to-use-fips-140-2-validated-ciphers-openssh-config/13187/5 "2024-03-14T00:17:30Z")

</div>

> [@sagarseapatil](#):
>
> Can we ignore this control?

> [@sagarseapatil](#):
>
> So do we apply these controls or treat them as false positives.

In my opinion, you should be discussing this with your information security team and/or auditors. Anything related to “false positives” or applying a security configuration or having a system fall under some sort of compliance is a discussion between yourself and information security professionals whom you work with.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex020/uploads/rockylinux/original/1X/91b7219eec10e30013422e4df76c1d898711a5d5.svg) [@system](https://forums.rockylinux.org/u/system)\
**Post date:** [May 13, 2024, 12:17am UTC](https://forums.rockylinux.org/t/stig-configure-ssh-client-to-use-fips-140-2-validated-ciphers-openssh-config/13187/6 "2024-05-13T00:17:37Z")

</div>

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.
