SRG-OS-000033-GPOS-00014 Controls

STIG IDVersionTitleProduct
ALMA-09-003650V1R1AlmaLinux OS 9 must force a frequent session key renegotiation for SSH connections to the server.
ALMA-09-003870V1R1AlmaLinux OS 9 IP tunnels must use FIPS 140-3 approved cryptographic algorithms.
ALMA-09-004310V1R1AlmaLinux OS 9 must use the TuxCare FIPS repository.
ALMA-09-004320V1R1AlmaLinux OS 9 must use the TuxCare FIPS packages and not the default encryption packages.
ALMA-09-004420V1R1AlmaLinux OS 9 must enable FIPS mode.
UBTU-18-010411V2R15The Ubuntu operating system must implement DoD-approved encryption to protect the confidentiality of remote access sessions.
UBTU-24-100820V1R1Ubuntu 24.04 LTS must configure the SSH daemon to use FIPS 140-3 approved ciphers to prevent the unauthorized disclosure of information and/or detect changes to information during transmission.
UBTU-24-100840V1R1Ubuntu 24.04 LTS SSH server must be configured to use only FIPS 140-3 validated key exchange algorithms.
WN22-CC-000370V2R1Windows Server 2022 Remote Desktop Services must require secure Remote Procedure Call (RPC) communications.
WN22-CC-000380V2R1Windows Server 2022 Remote Desktop Services must be configured with the client connection encryption set to High Level.
WN10-CC-000290V2R8Remote Desktop Services must be configured with the client connection encryption set to the required level.
APPL-15-000054V1R1The macOS system must limit SSHD to FIPS-compliant connections.
APPL-15-000057V1R1The macOS system must limit SSH to FIPS-compliant connections.
APPL-14-000054V2R1The macOS system must limit SSHD to FIPS-compliant connections.
APPL-14-000057V2R1The macOS system must limit SSH to FIPS-compliant connections.
WN11-CC-000290V2R1Remote Desktop Services must be configured with the client connection encryption set to the required level.
UBTU-22-255050V2R1Ubuntu 22.04 LTS must configure the SSH daemon to use FIPSĀ 140-3-approved ciphers to prevent the unauthorized disclosure of information and/or detect changes to information during transmission.
UBTU-22-255060V2R1Ubuntu 22.04 LTS SSH server must be configured to use only FIPS-validated key exchange algorithms.
RHEL-08-010020V1R9RHEL 8 must implement NIST FIPS-validated cryptography for the following: to provision digital signatures, to generate cryptographic hashes, and to protect data requiring data-at-rest protections in accordance with applicable federal laws, Executive Orders, directives, policies, regulations, and standards.
RHEL-08-040161V1R9RHEL 8 must force a frequent session key renegotiation for SSH connections to the server.
RHEL-07-021350V3R8The Red Hat Enterprise Linux operating system must implement NIST FIPS-validated cryptography for the following: to provision digital signatures, to generate cryptographic hashes, and to protect data requiring data-at-rest protections in accordance with applicable federal laws, Executive Orders, directives, policies, regulations, and standards.
RHEL-07-040110V3R8The Red Hat Enterprise Linux 7 operating system must implement DoD-approved encryption to protect the confidentiality of SSH connections.
RHEL-09-671010V2R1RHEL 9 must enable FIPS mode.
RHEL-09-671020V2R1RHEL 9 IP tunnels must use FIPS 140-2/140-3 approved cryptographic algorithms.
OL09-00-000070V1R1OL 9 must enable FIPS mode.
OL09-00-002404V1R1OL 9 IP tunnels must use 140-3 approved cryptographic algorithms.
WN16-SO-000430V2R10Windows Server 2016 must be configured to use FIPS-compliant algorithms for encryption, hashing, and signing.
SLES-15-010160V1R9The SUSE operating system must implement DoD-approved encryption to protect the confidentiality of SSH remote connections.
SLES-12-030170V2R13The SUSE operating system must implement DoD-approved encryption to protect the confidentiality of SSH remote connections.
OL07-00-021350V2R14The Oracle Linux operating system must implement NIST FIPS-validated cryptography for the following: to provision digital signatures, to generate cryptographic hashes, and to protect data requiring data-at-rest protections in accordance with applicable federal laws, Executive Orders, directives, policies, regulations, and standards.
OL07-00-040110V2R14The Oracle Linux 7 operating system must implement DoD-approved encryption to protect the confidentiality of SSH connections.
OL07-00-040712V2R14The Oracle Linux operating system SSH server must be configured to use only FIPS-validated key exchange algorithms.
WN19-CC-000370V2R8Windows Server 2019 Remote Desktop Services must require secure Remote Procedure Call (RPC) communications.
WN19-CC-000380V2R8Windows Server 2019 Remote Desktop Services must be configured with the client connection encryption set to High Level.
OL08-00-010020V1R9OL 8 must implement NIST FIPS-validated cryptography for the following: To provision digital signatures, to generate cryptographic hashes, and to protect data requiring data-at-rest protections in accordance with applicable federal laws, Executive Orders, directives, policies, regulations, and standards.
OL08-00-040161V1R9OL 8 must force a frequent session key renegotiation for SSH connections to the server.