STIGhubSTIGhub
STIGsRMF ControlsCompare

STIGhub

A free tool to search and browse the entire DISA STIG library. Saves up to 75% in security compliance research time.

Navigation

  • Browse STIGs
  • Search
  • RMF Controls
  • Compare Versions

Resources

  • About
  • Release Notes
  • VPAT
  • DISA STIG Library
STIGs updated 5 hours ago
Powered by Pylon
© 2026 Beacon Cloud Solutions, Inc. All rights reserved.
← Back to Oracle Linux 8 Security Technical Implementation Guide

V-248868

CAT II (Medium)

OL 8 must force a frequent session key renegotiation for SSH connections to the server.

Rule ID

SV-248868r958408_rule

STIG

Oracle Linux 8 Security Technical Implementation Guide

Version

V2R8

CCIs

CCI-000068

Discussion

Unapproved mechanisms that are used for authentication to the cryptographic module are not verified and therefore cannot be relied on to provide confidentiality or integrity, and DOD data may be compromised. Session key regeneration limits the chances of a session key becoming compromised.

Check Content

Verify the SSH server is configured to force frequent session key renegotiation with the following command:

$ sudo /usr/sbin/sshd -dd 2>&1 | awk '/filename/ {print $4}' | tr -d '\r' | tr '\n' ' ' | xargs sudo grep -iH '^\s*rekeylimit'

RekeyLimit 1G 1h

If "RekeyLimit" does not have a maximum data amount and maximum time defined or is missing or commented out, this is a finding.

If conflicting results are returned, this is a finding.

Fix Text

Configure the system to force a frequent session key renegotiation for SSH connections to the server by adding or modifying the following line in the "/etc/ssh/sshd_config" file: 
 
RekeyLimit 1G 1h 
 
The SSH daemon must be restarted for the settings to take effect. 
 
$ sudo systemctl restart sshd.service