diff --git a/linux_os/guide/services/ssh/ssh_server/sshd_use_approved_ciphers/rule.yml b/linux_os/guide/services/ssh/ssh_server/sshd_use_approved_ciphers/rule.yml index c3a892312d71..91bb30a4057f 100644 --- a/linux_os/guide/services/ssh/ssh_server/sshd_use_approved_ciphers/rule.yml +++ b/linux_os/guide/services/ssh/ssh_server/sshd_use_approved_ciphers/rule.yml @@ -1,6 +1,6 @@ documentation_complete: true -prodtype: wrlinux8,wrlinux1019,rhel6,rhel7,rhel8,ol7,rhv4 +prodtype: wrlinux8,wrlinux1019,rhel6,rhel7,ol7,rhv4 title: 'Use Only FIPS 140-2 Validated Ciphers' diff --git a/linux_os/guide/services/ssh/ssh_server/sshd_use_approved_macs/rule.yml b/linux_os/guide/services/ssh/ssh_server/sshd_use_approved_macs/rule.yml index a5ad34d76088..390e71cc7966 100644 --- a/linux_os/guide/services/ssh/ssh_server/sshd_use_approved_macs/rule.yml +++ b/linux_os/guide/services/ssh/ssh_server/sshd_use_approved_macs/rule.yml @@ -1,6 +1,6 @@ documentation_complete: true -prodtype: wrlinux1019,rhel6,rhel7,rhel8,ol7,rhv4 +prodtype: wrlinux1019,rhel6,rhel7,ol7,rhv4 title: 'Use Only FIPS 140-2 Validated MACs' diff --git a/rhel8/profiles/ospp.profile b/rhel8/profiles/ospp.profile index 715e17de4ae3..2599a0a14090 100644 --- a/rhel8/profiles/ospp.profile +++ b/rhel8/profiles/ospp.profile @@ -1034,16 +1034,9 @@ selections: ## Enable SSH Warning Banner - sshd_enable_warning_banner - ## Use Only FIPS 140-2 Validated Ciphers - - sshd_use_approved_ciphers - ## TO DO: https://github.com/ComplianceAsCode/content/issues/4469 #echo -e "PubkeyAcceptedKeyTypes ssh-rsa,ecdsa-sha2-nistp256,ecdsa-sha2-nistp384" >> $CONFIG - ## Use Only FIPS 140-2 Validated MACs - ## SEE ALSO: https://github.com/ComplianceAsCode/content/issues/4470 - - sshd_use_approved_macs - ## TO DO: https://github.com/ComplianceAsCode/content/issues/4471 #echo -e "KexAlgorithms diffie-hellman-group14-sha1,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521" >> $CONFIG @@ -1091,6 +1084,10 @@ selections: ## Enable FIPS Mode - enable_fips_mode + ## Set up Crypto policy + - var_system_crypto_policy=fips + - configure_crypto_policy + ## TO DO: https://github.com/ComplianceAsCode/content/issues/4500 # - sysctl_crypto_fips_enabled