There isn't CRYPTO_POLICY= variable in RHEL 9. To opt-out crypto-policies, CU can set their settings in /etc/ssh/sshd_config.d/. See "Steps of overriding crypto policies for RHEL9" in following KCS https://access.redhat.com/solutions/4410591 Reported by: rh-ee-kmoriwak https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/9/html/securing_networks/assembly_using-secure-communications-between-two-systems-with-openssh_securing-networks#annotations:6967a0ec-085a-4da0-9a06-a45d2f781f38
The fix is available on the Customer Portal: https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/9/html/securing_networks/assembly_using-secure-communications-between-two-systems-with-openssh_securing-networks#making-openssh-more-secure_assembly_using-secure-communications-between-two-systems-with-openssh Thank you for the report.