SRG-OS-000125-GPOS-00065 Controls

STIG IDVersionTitleProduct
SLES-15-010270V1R4The SUSE operating system SSH daemon must be configured to only use Message Authentication Codes (MACs) employing FIPS 140-2 approved cryptographic hash algorithms.
WN19-CC-000470V3R1Windows Server 2019 Windows Remote Management (WinRM) client must not use Basic authentication.
WN19-CC-000490V3R1Windows Server 2019 Windows Remote Management (WinRM) client must not use Digest authentication.
WN19-CC-000500V3R1Windows Server 2019 Windows Remote Management (WinRM) service must not use Basic authentication.
UBTU-18-010414V2R12The Ubuntu operating system must use strong authenticators in establishing nonlocal maintenance and diagnostic sessions.
UBTU-20-010035V1R6The Ubuntu operating system must use strong authenticators in establishing nonlocal maintenance and diagnostic sessions.
SLES-12-030180V3R1The SUSE operating system SSH daemon must be configured to only use Message Authentication Codes (MACs) employing FIPS 140-2 approved cryptographic hash algorithms.
ALMA-09-040390V1R1AlmaLinux OS 9 must enable the Pluggable Authentication Module (PAM) interface for SSHD.
OL08-00-010290V1R6The OL 8 SSH server must be configured to use only Message Authentication Codes (MACs) employing FIPS 140-2 validated cryptographic hash algorithms.
OL08-00-010291V1R6The OL 8 SSH server must be configured to use only ciphers employing FIPS 140-2 validated cryptographic algorithms.
OL09-00-002344V1R1OL 9 must enable the Pluggable Authentication Module (PAM) interface for SSHD.
UBTU-24-500050V1R1Ubuntu 24.04 LTS must use strong authenticators in establishing nonlocal maintenance and diagnostic sessions.
UBTU-22-255065V1R1Ubuntu 22.04 LTS must use strong authenticators in establishing nonlocal maintenance and diagnostic sessions.
WN11-CC-000330V1R6The Windows Remote Management (WinRM) client must not use Basic authentication.
WN11-CC-000345V1R6The Windows Remote Management (WinRM) service must not use Basic authentication.
WN11-CC-000360V1R6The Windows Remote Management (WinRM) client must not use Digest authentication.
RHEL-09-255050V2R5RHEL 9 must enable the Pluggable Authentication Module (PAM) interface for SSHD.
WN10-CC-000330V3R1The Windows Remote Management (WinRM) client must not use Basic authentication.
WN10-CC-000345V3R1The Windows Remote Management (WinRM) service must not use Basic authentication.
WN10-CC-000360V3R1The Windows Remote Management (WinRM) client must not use Digest authentication.
WN16-CC-000500V2R9The Windows Remote Management (WinRM) client must not use Basic authentication.
WN16-CC-000520V2R9The Windows Remote Management (WinRM) client must not use Digest authentication.
WN16-CC-000530V2R9The Windows Remote Management (WinRM) service must not use Basic authentication.
WN22-CC-000470V2R5Windows Server 2022 Windows Remote Management (WinRM) client must not use Basic authentication.
WN22-CC-000490V2R5Windows Server 2022 Windows Remote Management (WinRM) client must not use Digest authentication.
WN22-CC-000500V2R5Windows Server 2022 Windows Remote Management (WinRM) service must not use Basic authentication.