Signed-off-by: Maura Dailey <[email protected]>
---
 RHEL6/input/checks/sshd_banner_set.xml             |   24 +++++++--------
 RHEL6/input/checks/sshd_clientalivecountmax.xml    |   32 ++++++++-----------
 .../input/checks/sshd_hostbasedauthentication.xml  |   19 ++++++++----
 RHEL6/input/checks/sshd_idle_timeout.xml           |   30 ++++++++++--------
 RHEL6/input/checks/sshd_no_user_envset.xml         |   24 ++++++--------
 .../input/checks/sshd_permitemptypasswords_no.xml  |   24 +++++++--------
 RHEL6/input/checks/sshd_permitrootlogin_no.xml     |   24 +++++++--------
 RHEL6/input/checks/sshd_protocol_2.xml             |   17 +++++++---
 RHEL6/input/checks/sshd_rsh_emulation_disabled.xml |   24 +++++++--------
 RHEL6/input/checks/sshd_use_approved_ciphers.xml   |   28 ++++++++++-------
 10 files changed, 126 insertions(+), 120 deletions(-)

diff --git a/RHEL6/input/checks/sshd_banner_set.xml 
b/RHEL6/input/checks/sshd_banner_set.xml
index 73ca063..fca2781 100644
--- a/RHEL6/input/checks/sshd_banner_set.xml
+++ b/RHEL6/input/checks/sshd_banner_set.xml
@@ -1,33 +1,31 @@
 <def-group>
-  <definition class="compliance"
-  id="sshd_banner_set" version="1">
+  <definition class="compliance" id="sshd_banner_set" version="1">
     <metadata>
       <title>Enable a Warning Banner</title>
       <affected family="unix">
         <platform>Red Hat Enterprise Linux 6</platform>
       </affected>
-      <description>SSH warning banner should be enabled (and
-      dependencies are met)</description>
+      <description>SSH warning banner should be enabled (and dependencies are
+      met)</description>
+      <reference source="MED" ref_id="20130813" ref_url="test_attestation" />
     </metadata>
     <criteria comment="SSH is not being used or conditions are met"
     operator="OR">
       <extend_definition comment="sshd service is disabled"
       definition_ref="service_sshd_disabled" />
-      <criterion comment="Conditions are satisfied"
-      test_ref="test_20245" />
+      <criterion comment="Check Banner in /etc/ssh/sshd_config"
+      test_ref="test_sshd_banner_set" />
     </criteria>
   </definition>
-  <ind:textfilecontent54_test check="all"
-  check_existence="all_exist"
+  <ind:textfilecontent54_test check="all" check_existence="all_exist"
   comment="Tests the value of the Banner[\s]+/etc/issue setting in the 
/etc/ssh/sshd_config file"
-  id="test_20245" version="1">
-    <ind:object object_ref="obj_20245" />
+  id="test_sshd_banner_set" version="1">
+    <ind:object object_ref="obj_sshd_banner_set" />
   </ind:textfilecontent54_test>
-  <ind:textfilecontent54_object id="obj_20245"
-  version="1">
+  <ind:textfilecontent54_object id="obj_sshd_banner_set" version="1">
     <ind:path>/etc/ssh</ind:path>
     <ind:filename>sshd_config</ind:filename>
-    <ind:pattern operation="pattern 
match">^[\s]*Banner[\s]+/etc/issue$</ind:pattern>
+    <ind:pattern operation="pattern 
match">^[\s]*(?i)Banner(?-i)[\s]+/etc/issue[\s]*$</ind:pattern>
     <ind:instance datatype="int">1</ind:instance>
   </ind:textfilecontent54_object>
 </def-group>
diff --git a/RHEL6/input/checks/sshd_clientalivecountmax.xml 
b/RHEL6/input/checks/sshd_clientalivecountmax.xml
index 1aedbf5..22ba8e9 100644
--- a/RHEL6/input/checks/sshd_clientalivecountmax.xml
+++ b/RHEL6/input/checks/sshd_clientalivecountmax.xml
@@ -1,39 +1,35 @@
 <def-group>
-  <definition class="compliance"
-  id="sshd_clientalivecountmax" version="1">
+  <definition class="compliance" id="sshd_clientalivecountmax" version="1">
     <metadata>
       <title>Set ClientAliveCountMax for User Logins</title>
       <affected family="unix">
         <platform>Red Hat Enterprise Linux 6</platform>
       </affected>
-      <description>The SSH ClientAliveCountMax should be set to an
-      appropriate value (and dependencies are met)</description>
+      <description>The SSH ClientAliveCountMax should be set to an appropriate
+      value (and dependencies are met)</description>
+      <reference source="MED" ref_id="20130813" ref_url="test_attestation" />
     </metadata>
     <criteria comment="SSH is not being used or conditions are met"
     operator="OR">
       <extend_definition comment="sshd service is disabled"
       definition_ref="service_sshd_disabled" />
-      <criterion comment="check ClientAliveCountMax in /etc/ssh/sshd_config"
-      test_ref="test_20240" />
+      <criterion comment="Check ClientAliveCountMax in /etc/ssh/sshd_config"
+      test_ref="test_sshd_clientalivecountmax" />
     </criteria>
   </definition>
-  <ind:textfilecontent54_test check="all"
-  check_existence="all_exist"
+  <ind:textfilecontent54_test check="all" check_existence="all_exist"
   comment="Tests the value of the ClientAliveCountMax setting in the 
/etc/ssh/sshd_config file"
-  id="test_20240" version="1">
-    <ind:object object_ref="obj_20240" />
-    <ind:state state_ref="state_20240" />
+  id="test_sshd_clientalivecountmax" version="1">
+    <ind:object object_ref="obj_sshd_clientalivecountmax" />
+    <ind:state state_ref="state_sshd_clientalivecountmax" />
   </ind:textfilecontent54_test>
-  <ind:textfilecontent54_state id="state_20240"
-  version="1">
-    <ind:subexpression datatype="int" operation="equals">
-    0</ind:subexpression>
+  <ind:textfilecontent54_state id="state_sshd_clientalivecountmax" version="1">
+    <ind:subexpression datatype="int" operation="equals">0</ind:subexpression>
   </ind:textfilecontent54_state>
-  <ind:textfilecontent54_object id="obj_20240"
-  version="1">
+  <ind:textfilecontent54_object id="obj_sshd_clientalivecountmax" version="1">
     <ind:path>/etc/ssh</ind:path>
     <ind:filename>sshd_config</ind:filename>
-    <ind:pattern operation="pattern 
match">^[\s]*ClientAliveCountMax[\s]*([\d]+)</ind:pattern>
+    <ind:pattern operation="pattern 
match">^[\s]*(?i)ClientAliveCountMax[\s]+([\d]+)[\s]*$</ind:pattern>
     <ind:instance datatype="int">1</ind:instance>
   </ind:textfilecontent54_object>
 </def-group>
diff --git a/RHEL6/input/checks/sshd_hostbasedauthentication.xml 
b/RHEL6/input/checks/sshd_hostbasedauthentication.xml
index 1b5901b..f3143e7 100644
--- a/RHEL6/input/checks/sshd_hostbasedauthentication.xml
+++ b/RHEL6/input/checks/sshd_hostbasedauthentication.xml
@@ -6,18 +6,25 @@
         <platform>Red Hat Enterprise Linux 6</platform>
       </affected>
       <description>SSH host-based authentication should be 
disabled.</description>
+      <reference source="MED" ref_id="20130813" ref_url="test_attestation" />
     </metadata>
-    <criteria comment="SSH is not being used or conditions are met" 
operator="OR">
-      <extend_definition comment="sshd service is disabled" 
definition_ref="service_sshd_disabled" />
-      <criterion comment="Conditions are satisfied" 
test_ref="test_sshd_hostbasedauthentication" />
+    <criteria comment="SSH is not being used or conditions are met"
+    operator="OR">
+      <extend_definition comment="sshd service is disabled"
+      definition_ref="service_sshd_disabled" />
+      <criterion comment="Check HostbasedAuthentication in 
/etc/ssh/sshd_config"
+      test_ref="test_sshd_hostbasedauthentication" />
     </criteria>
   </definition>
-  <ind:textfilecontent54_test check="all" check_existence="none_exist" 
comment="sshd HostbasedAuthentication" id="test_sshd_hostbasedauthentication" 
version="1">
+  <ind:textfilecontent54_test check="all" check_existence="none_exist"
+  comment="sshd HostbasedAuthentication" id="test_sshd_hostbasedauthentication"
+  version="1">
     <ind:object object_ref="object_sshd_hostbasedauthentication" />
   </ind:textfilecontent54_test>
   <ind:textfilecontent54_object id="object_sshd_hostbasedauthentication" 
version="1">
-    <ind:filepath>/etc/ssh/sshd_config</ind:filepath>
-    <ind:pattern operation="pattern 
match">^\s*HostbasedAuthentication\s+yes\s*$</ind:pattern>
+    <ind:path>/etc/ssh</ind:path>
+    <ind:filename>sshd_config</ind:filename>
+    <ind:pattern operation="pattern 
match">^[\s]*(?i)HostbasedAuthentication[\s]+yes[\s]*$</ind:pattern>
     <ind:instance datatype="int">1</ind:instance>
   </ind:textfilecontent54_object>
 </def-group>
diff --git a/RHEL6/input/checks/sshd_idle_timeout.xml 
b/RHEL6/input/checks/sshd_idle_timeout.xml
index 984c630..a75173e 100644
--- a/RHEL6/input/checks/sshd_idle_timeout.xml
+++ b/RHEL6/input/checks/sshd_idle_timeout.xml
@@ -7,28 +7,32 @@
       </affected>
       <description>The SSH idle timeout interval should be set to an
       appropriate value.</description>
+      <reference source="MED" ref_id="20130813" ref_url="test_attestation" />
     </metadata>
-    <criteria comment="sshd service disabled or timeout set" operator="OR">
-      <extend_definition comment="sshd service is disabled" 
definition_ref="service_sshd_disabled" />
-      <criterion comment="check ClientAliveInterval in /etc/ssh/sshd_config" 
test_ref="test_sshd_idle_timeout" />
+    <criteria comment="SSH is not being used or conditions are met"
+    operator="OR">
+      <extend_definition comment="sshd service is disabled"
+      definition_ref="service_sshd_disabled" />
+      <criterion comment="Check ClientAliveInterval in /etc/ssh/sshd_config"
+      test_ref="test_sshd_idle_timeout" />
     </criteria>
   </definition>
-
-  <ind:textfilecontent54_test check="all" check_existence="all_exist" 
comment="timeout is configured" id="test_sshd_idle_timeout" version="1">
+  <ind:textfilecontent54_test check="all" check_existence="all_exist"
+  comment="timeout is configured" id="test_sshd_idle_timeout" version="1">
     <ind:object object_ref="object_sshd_idle_timeout" />
     <ind:state state_ref="state_timeout_value" />
   </ind:textfilecontent54_test>
-
   <ind:textfilecontent54_object id="object_sshd_idle_timeout" version="1">
     <ind:path>/etc/ssh</ind:path>
     <ind:filename>sshd_config</ind:filename>
-    <ind:pattern operation="pattern 
match">^\s*ClientAliveInterval\s+(\d+)\s*$</ind:pattern>
-    <ind:instance datatype="int">1</ind:instance> 
+    <ind:pattern operation="pattern 
match">^[\s]*(?i)ClientAliveInterval[\s]+(\d+)[\s]*$</ind:pattern>
+    <ind:instance datatype="int">1</ind:instance>
   </ind:textfilecontent54_object>
-
-  <ind:textfilecontent54_state comment="ClientAliveInterval in seconds" 
id="state_timeout_value" version="1">
-    <ind:subexpression datatype="int" operation="equals" var_check="all" 
var_ref="sshd_idle_timeout_value" />
+  <ind:textfilecontent54_state comment="ClientAliveInterval in seconds"
+  id="state_timeout_value" version="1">
+    <ind:subexpression datatype="int" operation="equals" var_check="all"
+    var_ref="sshd_idle_timeout_value" />
   </ind:textfilecontent54_state>
-
-  <external_variable comment="timeout value" datatype="int" 
id="sshd_idle_timeout_value" version="1" />
+  <external_variable comment="timeout value" datatype="int"
+  id="sshd_idle_timeout_value" version="1" />
 </def-group>
diff --git a/RHEL6/input/checks/sshd_no_user_envset.xml 
b/RHEL6/input/checks/sshd_no_user_envset.xml
index 985395e..ce128a9 100644
--- a/RHEL6/input/checks/sshd_no_user_envset.xml
+++ b/RHEL6/input/checks/sshd_no_user_envset.xml
@@ -1,34 +1,30 @@
 <def-group>
-  <definition class="compliance"
-  id="sshd_no_user_envset" version="1">
+  <definition class="compliance" id="sshd_no_user_envset" version="1">
     <metadata>
       <title>Do Not Allow Users to Set Environment Options</title>
       <affected family="unix">
         <platform>Red Hat Enterprise Linux 6</platform>
       </affected>
-      <description>PermitUserEnvironment should be
-      disabled</description>
+      <description>PermitUserEnvironment should be disabled</description>
+      <reference source="MED" ref_id="20130813" ref_url="test_attestation" />
     </metadata>
     <criteria comment="SSH is not being used or conditions are met"
     operator="OR">
       <extend_definition comment="sshd service is disabled"
       definition_ref="service_sshd_disabled" />
-      <criterion comment="Check value of PermitUserEnvironment in 
/etc/ssh/sshd_config"
-      negate="true"
-      test_ref="test_202455" />
+      <criterion comment="Check PermitUserEnvironment in /etc/ssh/sshd_config"
+      negate="true" test_ref="test_sshd_no_user_envset" />
     </criteria>
   </definition>
-  <ind:textfilecontent54_test check="all"
-  check_existence="none_exist"
+  <ind:textfilecontent54_test check="all" check_existence="none_exist"
   comment="Check value of PermitUserEnvironment in /etc/ssh/sshd_config"
-  id="test_202455" version="1">
-    <ind:object object_ref="obj_202455" />
+  id="test_sshd_no_user_envset" version="1">
+    <ind:object object_ref="obj_sshd_no_user_envset" />
   </ind:textfilecontent54_test>
-  <ind:textfilecontent54_object id="obj_202455"
-  version="1">
+  <ind:textfilecontent54_object id="obj_sshd_no_user_envset" version="1">
     <ind:path>/etc/ssh</ind:path>
     <ind:filename>sshd_config</ind:filename>
-    <ind:pattern operation="pattern 
match">^[\s]*[Pp][Ee][Rr][Mm][Ii][Tt][Uu][Ss][Ee][Rr][Ee][Nn][Vv][Ii][Rr][Oo][Nn][Mm][Ee][Nn][Tt][\s]+[Nn][Oo]\s*$</ind:pattern>
+    <ind:pattern operation="pattern 
match">^[\s]*(?i)PermitUserEnvironment[\s]+no[\s]*$</ind:pattern>
     <ind:instance datatype="int">1</ind:instance>
   </ind:textfilecontent54_object>
 </def-group>
diff --git a/RHEL6/input/checks/sshd_permitemptypasswords_no.xml 
b/RHEL6/input/checks/sshd_permitemptypasswords_no.xml
index 3795e4b..a2abe9b 100644
--- a/RHEL6/input/checks/sshd_permitemptypasswords_no.xml
+++ b/RHEL6/input/checks/sshd_permitemptypasswords_no.xml
@@ -1,34 +1,32 @@
 <def-group>
-  <definition class="compliance"
-  id="sshd_permitemptypasswords_no" version="1">
+  <definition class="compliance" id="sshd_permitemptypasswords_no" version="1">
     <metadata>
       <title>Disable Empty Passwords</title>
       <affected family="unix">
         <platform>Red Hat Enterprise Linux 6</platform>
       </affected>
-      <description>Remote connections from accounts with empty
-      passwords should be disabled (and dependencies are
-      met)</description>
+      <description>Remote connections from accounts with empty passwords should
+      be disabled (and dependencies are met)</description>
+      <reference source="MED" ref_id="20130813" ref_url="test_attestation" />
     </metadata>
     <criteria comment="SSH is not being used or conditions are met"
     operator="OR">
       <extend_definition comment="sshd service is disabled"
       definition_ref="service_sshd_disabled" />
-      <criterion comment="Conditions are satisfied" negate="true"
-      test_ref="test_20244" />
+      <criterion comment="Check PermitEmptyPasswords in /etc/ssh/sshd_config"
+      negate="true" test_ref="test_sshd_permitemptypasswords_no" />
     </criteria>
   </definition>
-  <ind:textfilecontent54_test check="all"
-  check_existence="none_exist"
+  <ind:textfilecontent54_test check="all" check_existence="none_exist"
   comment="Tests the value of the 
PermitEmptyPasswords[\s]*(&lt;:nocomment:&gt;*) setting in the 
/etc/ssh/sshd_config file"
-  id="test_20244" version="1">
-    <ind:object object_ref="obj_20244" />
+  id="test_sshd_permitemptypasswords_no" version="1">
+    <ind:object object_ref="obj_sshd_permitemptypasswords_no" />
   </ind:textfilecontent54_test>
-  <ind:textfilecontent54_object id="obj_20244"
+  <ind:textfilecontent54_object id="obj_sshd_permitemptypasswords_no"
   version="1">
     <ind:path>/etc/ssh</ind:path>
     <ind:filename>sshd_config</ind:filename>
-    <ind:pattern operation="pattern 
match">^[\s]*[Pp][Ee][Rr][Mm][Ii][Tt][Ee][Mm][Pp][Tt][Yy][Pp][Aa][Ss][Ss][Ww][Oo][Rr][Dd][Ss][\s]+[Nn][Oo]\s*$</ind:pattern>
+    <ind:pattern operation="pattern 
match">^[\s]*(?i)PermitEmptyPasswords[\s]+no[\s]*$</ind:pattern>
     <ind:instance datatype="int">1</ind:instance>
   </ind:textfilecontent54_object>
 </def-group>
diff --git a/RHEL6/input/checks/sshd_permitrootlogin_no.xml 
b/RHEL6/input/checks/sshd_permitrootlogin_no.xml
index d3c5f79..37f255f 100644
--- a/RHEL6/input/checks/sshd_permitrootlogin_no.xml
+++ b/RHEL6/input/checks/sshd_permitrootlogin_no.xml
@@ -1,33 +1,31 @@
 <def-group>
-  <definition class="compliance"
-  id="sshd_permitrootlogin_no" version="1">
+  <definition class="compliance" id="sshd_permitrootlogin_no" version="1">
     <metadata>
       <title>Disable root Login via SSH</title>
       <affected family="unix">
         <platform>Red Hat Enterprise Linux 6</platform>
       </affected>
-      <description>Root login via SSH should be disabled (and
-      dependencies are met)</description>
+      <description>Root login via SSH should be disabled (and dependencies are
+      met)</description>
+      <reference source="MED" ref_id="20130813" ref_url="test_attestation" />
     </metadata>
     <criteria comment="SSH is not being used or conditions are met"
     operator="OR">
       <extend_definition comment="sshd service is disabled"
       definition_ref="service_sshd_disabled" />
-      <criterion comment="Conditions are satisfied"
-      test_ref="test_20243" />
+      <criterion comment="Check PermitRootLogin in /etc/ssh/sshd_config"
+      test_ref="test_sshd_permitrootlogin_no" />
     </criteria>
   </definition>
-  <ind:textfilecontent54_test check="all"
-  check_existence="none_exist"
+  <ind:textfilecontent54_test check="all" check_existence="none_exist"
   comment="Tests the value of the PermitRootLogin[\s]*(&lt;:nocomment:&gt;*) 
setting in the /etc/ssh/sshd_config file"
-  id="test_20243" version="1">
-    <ind:object object_ref="obj_20243" />
+  id="test_sshd_permitrootlogin_no" version="1">
+    <ind:object object_ref="obj_sshd_permitrootlogin_no" />
   </ind:textfilecontent54_test>
-  <ind:textfilecontent54_object id="obj_20243"
-  version="1">
+  <ind:textfilecontent54_object id="obj_sshd_permitrootlogin_no" version="1">
     <ind:path>/etc/ssh</ind:path>
     <ind:filename>sshd_config</ind:filename>
-    <ind:pattern operation="pattern 
match">^[\s]*[Pp][Ee][Rr][Mm][Ii][Tt][Rr][Oo][Oo][Tt][Ll][Oo][Gg][Ii][Nn][\s]*yes</ind:pattern>
+    <ind:pattern operation="pattern 
match">^[\s]*(?i)PermitRootLogin[\s]+yes[\s]*$</ind:pattern>
     <ind:instance datatype="int">1</ind:instance>
   </ind:textfilecontent54_object>
 </def-group>
diff --git a/RHEL6/input/checks/sshd_protocol_2.xml 
b/RHEL6/input/checks/sshd_protocol_2.xml
index 635b936..16785da 100644
--- a/RHEL6/input/checks/sshd_protocol_2.xml
+++ b/RHEL6/input/checks/sshd_protocol_2.xml
@@ -6,18 +6,25 @@
         <platform>Red Hat Enterprise Linux 6</platform>
       </affected>
       <description>The OpenSSH daemon should be running protocol 
2.</description>
+      <reference source="MED" ref_id="20130813" ref_url="test_attestation" />
     </metadata>
     <criteria comment="SSH is not being used or conditions are met" 
operator="OR">
-      <extend_definition comment="rpm package openssh-server removed" 
definition_ref="package_openssh-server_removed" />
-      <criterion comment="/etc/ssh/sshd_config configured for protocol 2" 
test_ref="test_sshd_protocol_2" />
+      <extend_definition comment="sshd service is disabled"
+      definition_ref="service_sshd_disabled" />
+      <extend_definition comment="rpm package openssh-server removed"
+      definition_ref="package_openssh-server_removed" />
+      <criterion comment="Check Protocol in /etc/ssh/sshd_config"
+      test_ref="test_sshd_protocol_2" />
     </criteria>
   </definition>
-  <ind:textfilecontent54_test check="all" check_existence="all_exist" 
comment="sshd uses protocol 2" id="test_sshd_protocol_2" version="1">
+  <ind:textfilecontent54_test check="all" check_existence="all_exist"
+  comment="sshd uses protocol 2" id="test_sshd_protocol_2" version="1">
     <ind:object object_ref="object_sshd_protocol_2" />
   </ind:textfilecontent54_test>
   <ind:textfilecontent54_object id="object_sshd_protocol_2" version="2">
-    <ind:filepath>/etc/ssh/sshd_config</ind:filepath>
-    <ind:pattern operation="pattern match">^\s*Protocol\s+2\s*$</ind:pattern>
+    <ind:path>/etc/ssh</ind:path>
+    <ind:filename>sshd_config</ind:filename>
+    <ind:pattern operation="pattern 
match">^[\s]*(?i)Protocol[\s]+2[\s]*$</ind:pattern>
     <ind:instance datatype="int">1</ind:instance>
   </ind:textfilecontent54_object>
 </def-group>
diff --git a/RHEL6/input/checks/sshd_rsh_emulation_disabled.xml 
b/RHEL6/input/checks/sshd_rsh_emulation_disabled.xml
index 0d85a16..fb15c10 100644
--- a/RHEL6/input/checks/sshd_rsh_emulation_disabled.xml
+++ b/RHEL6/input/checks/sshd_rsh_emulation_disabled.xml
@@ -1,34 +1,32 @@
 <def-group>
-  <definition class="compliance"
-  id="sshd_rsh_emulation_disabled" version="1">
+  <definition class="compliance" id="sshd_rsh_emulation_disabled" version="1">
     <metadata>
       <title>Disable .rhosts Files</title>
       <affected family="unix">
         <platform>Red Hat Enterprise Linux 6</platform>
       </affected>
-      <description>Emulation of the rsh command through the ssh
-      server should be disabled (and dependencies are
-      met)</description>
+      <description>Emulation of the rsh command through the ssh server should
+      be disabled (and dependencies are met)</description>
+      <reference source="MED" ref_id="20130813" ref_url="test_attestation" />
     </metadata>
     <criteria comment="SSH is not being used or conditions are met"
     operator="OR">
       <extend_definition comment="sshd service is disabled"
       definition_ref="service_sshd_disabled" />
-      <criterion comment="Conditions are satisfied"
-      test_ref="test_20241" />
+      <criterion comment="Check IgnoreRhosts in /etc/ssh/sshd_config"
+      test_ref="test_sshd_rsh_emulation_disabled" />
     </criteria>
   </definition>
-  <ind:textfilecontent54_test check="all"
-  check_existence="none_exist"
+  <ind:textfilecontent54_test check="all" check_existence="none_exist"
   comment="Tests the value of the IgnoreRhosts[\s]*(&lt;:nocomment:&gt;*) 
setting in the /etc/ssh/sshd_config file"
-  id="test_20241" version="1">
-    <ind:object object_ref="obj_20241" />
+  id="test_sshd_rsh_emulation_disabled" version="1">
+    <ind:object object_ref="obj_sshd_rsh_emulation_disabled" />
   </ind:textfilecontent54_test>
-  <ind:textfilecontent54_object id="obj_20241"
+  <ind:textfilecontent54_object id="obj_sshd_rsh_emulation_disabled"
   version="1">
     <ind:path>/etc/ssh</ind:path>
     <ind:filename>sshd_config</ind:filename>
-    <ind:pattern operation="pattern 
match">^[\s]*[Ii][Gg][Nn][Oo][Rr][Ee][Rr][Hh][Oo][Ss][Tt][Ss][\s]*no\s*$</ind:pattern>
+    <ind:pattern operation="pattern 
match">^[\s]*(?i)IgnoreRhosts[\s]+no[\s]*$</ind:pattern>
     <ind:instance datatype="int">1</ind:instance>
   </ind:textfilecontent54_object>
 </def-group>
diff --git a/RHEL6/input/checks/sshd_use_approved_ciphers.xml 
b/RHEL6/input/checks/sshd_use_approved_ciphers.xml
index 1807d56..b6fc498 100644
--- a/RHEL6/input/checks/sshd_use_approved_ciphers.xml
+++ b/RHEL6/input/checks/sshd_use_approved_ciphers.xml
@@ -5,23 +5,27 @@
       <affected family="unix">
         <platform>Red Hat Enterprise Linux 6</platform>
       </affected>
-      <description>Limit the ciphers to those which are FIPS-approved and
-      only use ciphers in counter (CTR) mode.</description>
+      <description>Limit the ciphers to those which are FIPS-approved and only
+      use ciphers in counter (CTR) mode.</description>
+      <reference source="MED" ref_id="20130813" ref_url="test_attestation" />
     </metadata>
-    <criteria comment="SSH is not being used or conditions are met" 
operator="OR">
-      <!-- <extend_definition comment="sshd service is disabled" 
definition_ref="service_sshd_disabled" /> -->
-      <criterion comment="check ClientAliveInterval in /etc/ssh/sshd_config" 
test_ref="test_20251" />
+    <criteria comment="SSH is not being used or conditions are met"
+    operator="OR">
+      <extend_definition comment="sshd service is disabled"
+      definition_ref="service_sshd_disabled" />
+      <criterion comment="Check ClientAliveInterval in /etc/ssh/sshd_config"
+      test_ref="test_sshd_use_approved_ciphers" />
     </criteria>
   </definition>
-
-  <ind:textfilecontent54_test check="all" check_existence="all_exist" 
comment="tests the value of Ciphers setting in the /etc/ssh/sshd_config file" 
id="test_20251" version="1">
-    <ind:object object_ref="obj_20251" />
+  <ind:textfilecontent54_test check="all" check_existence="all_exist"
+  comment="tests the value of Ciphers setting in the /etc/ssh/sshd_config file"
+  id="test_sshd_use_approved_ciphers" version="1">
+    <ind:object object_ref="obj_sshd_use_approved_ciphers" />
   </ind:textfilecontent54_test>
-
-  <ind:textfilecontent54_object id="obj_20251" version="1">
+  <ind:textfilecontent54_object id="obj_sshd_use_approved_ciphers" version="1">
     <ind:path>/etc/ssh</ind:path>
     <ind:filename>sshd_config</ind:filename>
-    <ind:pattern operation="pattern 
match">^\s*Ciphers\s*aes128-ctr,aes192-ctr,aes256-ctr,aes128-cbc,3des-cbc,aes192-cbc,aes256-cbc\s*$</ind:pattern>
-    <ind:instance datatype="int">1</ind:instance> 
+    <ind:pattern operation="pattern 
match">^[\s]*(?i)Ciphers(?-i)[\s]+aes128-ctr,aes192-ctr,aes256-ctr,aes128-cbc,3des-cbc,aes192-cbc,aes256-cbc[\s]*$</ind:pattern>
+    <ind:instance datatype="int">1</ind:instance>
   </ind:textfilecontent54_object>
 </def-group>
-- 
1.7.1

_______________________________________________
scap-security-guide mailing list
[email protected]
https://lists.fedorahosted.org/mailman/listinfo/scap-security-guide

Reply via email to