mirror of
https://github.com/ansible-lockdown/RHEL9-CIS.git
synced 2026-03-25 14:27:12 +00:00
5 lines
349 B
Django/Jinja
5 lines
349 B
Django/Jinja
{{ file_managed_by_ansible }}
|
|
# This is a subpolicy to disable weak ciphers
|
|
# for the SSH protocol (libssh and OpenSSH)
|
|
# Carried out as part of CIS Benchmark rules combined 1.6.6 and 5.1.4
|
|
cipher@SSH ={% if rhel9cis_rule_1_6_6 %} -CHACHA20-POLY1305{% endif %}{% if rhel9cis_rule_5_1_4 %} -3DES-CBC -AES-128-CBC -AES-192-CBC -AES-256-CBC{% endif %}
|