Skip to content

Commit b4dd9c8

Browse files
authored
Merge pull request #14629 from alanmcanonical/cipher
Remove aes192-ctr
2 parents 1ad577e + 86e988d commit b4dd9c8

File tree

5 files changed

+7
-7
lines changed

5 files changed

+7
-7
lines changed

linux_os/guide/services/ssh/ssh_server/sshd_use_approved_ciphers_ordered_stig/bash/ubuntu.sh

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -3,7 +3,7 @@
33
{{%- if product == 'ubuntu2404' %}}
44
sshd_approved_ciphers="aes256-gcm@openssh.com,aes128-gcm@openssh.com,aes256-ctr,aes128-ctr"
55
{{%- elif product == 'ubuntu2204' %}}
6-
sshd_approved_ciphers="aes256-ctr,aes256-gcm@openssh.com,aes192-ctr,aes128-ctr,aes128-gcm@openssh.com"
6+
sshd_approved_ciphers="aes256-ctr,aes256-gcm@openssh.com,aes128-ctr,aes128-gcm@openssh.com"
77
{{%- else %}}
88
sshd_approved_ciphers="aes256-ctr,aes192-ctr,aes128-ctr"
99
{{%- endif %}}

linux_os/guide/services/ssh/ssh_server/sshd_use_approved_ciphers_ordered_stig/oval/ubuntu.xml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
{{%- if product == 'ubuntu2404' %}}
22
{{%- set sshd_approved_ciphers = "aes256-gcm@openssh.com,aes128-gcm@openssh.com,aes256-ctr,aes128-ctr" %}}
33
{{%- elif product == 'ubuntu2204' %}}
4-
{{%- set sshd_approved_ciphers = "aes256-ctr,aes256-gcm@openssh.com,aes192-ctr,aes128-ctr,aes128-gcm@openssh.com" %}}
4+
{{%- set sshd_approved_ciphers = "aes256-ctr,aes256-gcm@openssh.com,aes128-ctr,aes128-gcm@openssh.com" %}}
55
{{%- else %}}
66
{{%- set sshd_approved_ciphers = "aes256-ctr,aes192-ctr,aes128-ctr" %}}
77
{{%- endif %}}

linux_os/guide/services/ssh/ssh_server/sshd_use_approved_ciphers_ordered_stig/tests/common.sh

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -4,15 +4,15 @@
44
sshd_approved_ciphers="aes256-gcm@openssh.com,aes128-gcm@openssh.com,aes256-ctr,aes128-ctr"
55
sshd_scrambled_ciphers="aes128-gcm@openssh.com,aes256-gcm@openssh.com,aes256-ctr,aes128-ctr"
66
{{%- elif product == "ubuntu2204" %}}
7-
sshd_approved_ciphers="aes256-ctr,aes256-gcm@openssh.com,aes192-ctr,aes128-ctr,aes128-gcm@openssh.com"
8-
sshd_scrambled_ciphers="aes128-gcm@openssh.com,aes256-ctr,aes256-gcm@openssh.com,aes192-ctr,aes128-ctr"
7+
sshd_approved_ciphers="aes256-ctr,aes256-gcm@openssh.com,aes128-ctr,aes128-gcm@openssh.com"
8+
sshd_scrambled_ciphers="aes128-gcm@openssh.com,aes256-ctr,aes256-gcm@openssh.com,aes128-ctr"
99
{{%- else %}}
1010
sshd_approved_ciphers="aes256-ctr,aes192-ctr,aes128-ctr"
1111
sshd_scrambled_ciphers="aes128-ctr,aes192-ctr,aes256-ctr"
1212
{{%- endif %}}
1313

1414
for config_file in /etc/ssh/sshd_config /etc/ssh/sshd_config.d/*
15-
do
15+
do
1616
[[ -f "$config_file" ]] || continue
1717
sed -i "/^Ciphers.*/Id" "$config_file"
1818
done

linux_os/guide/services/ssh/ssh_server/sshd_use_approved_ciphers_ordered_stig/tests/correct_reduced_list.pass.sh

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -3,4 +3,4 @@
33

44
source common.sh
55

6-
echo "Ciphers aes192-ctr,aes128-ctr" >> /etc/ssh/sshd_config
6+
echo "Ciphers aes128-ctr" >> /etc/ssh/sshd_config

linux_os/guide/services/ssh/sshd_approved_ciphers.var

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -20,6 +20,6 @@ options:
2020
cis_sle12: chacha20-poly1305@openssh.com,aes256-gcm@openssh.com,aes128-gcm@openssh.com,aes256-ctr,aes192-ctr,aes128-ctr
2121
cis_sle15: chacha20-poly1305@openssh.com,aes256-gcm@openssh.com,aes128-gcm@openssh.com,aes256-ctr,aes192-ctr,aes128-ctr
2222
cis_ubuntu: chacha20-poly1305@openssh.com,aes128-ctr,aes192-ctr,aes256-ctr,aes128-gcm@openssh.com,aes256-gcm@openssh.com
23-
stig_ubuntu2204: aes256-ctr,aes256-gcm@openssh.com,aes192-ctr,aes128-ctr,aes128-gcm@openssh.com
23+
stig_ubuntu2204: aes256-ctr,aes256-gcm@openssh.com,aes128-ctr,aes128-gcm@openssh.com
2424
stig_ol9: aes256-gcm@openssh.com,aes256-ctr,aes128-gcm@openssh.com,aes128-ctr
2525
stig_ol8: aes256-gcm@openssh.com,aes256-ctr,aes128-gcm@openssh.com,aes128-ctr

0 commit comments

Comments
 (0)