Remediating ospp
on RHEL-10 results in sshd refusing connections
#12172
Labels
RHEL10
Red Hat Enterprise Linux 10 product related.
Description of problem:
results in a system that boots, but when I try to ssh into it, it seems to fail due to crypto policies:
commenting out the
Include
in/etc/ssh/sshd_config.d/40-redhat-crypto-policies.conf
gets me a working ssh connection.Other profiles (STIG) seem to work after I explicitly started generating RSA keys (RHEL-10 defaults to non-RSA), but that's with the
FIPS
crypto policies. Theospp
profile is special because it (as far as I know) usesFIPS:OSPP
, which might be somehow broken.Or maybe the bug is in how the content uses it. More investigation is likely needed.
SCAP Security Guide Version:
520a196
Additional Information/Debugging Steps:
I'm attaching the only artifact I have - the remediation HTML report. Not sure if it helps anything.
remediation.html.gz
The text was updated successfully, but these errors were encountered: