GEN005507 M6 - SSH Server MACs use FIPS 140-2 approved algorithms - 'MACS doesn't include HMAC-MD5/HMAC-RIPEMD160/HMAC-SHA1-96/HMAC-MD5-96'

Information

DoD information systems are required to use FIPS 140-2 approved cryptographic hash functions.

Solution

Open a terminal session and edit the SSH daemon configuration file '/etc/sshd_config' and remove any MACs other than 'hmac-sha1'. If there is no MACs line in '/etc/sshd_config', add 'MACs hmac-sha1' to the file.

Restart the SSH daemon for the changes to take effect.

See Also

http://iase.disa.mil/stigs/os/mac/u_mac_osx_10.6_v1r3_stig_20130426.zip

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-13, CAT|II, CCI|CCI-001453, Rule-ID|SV-39369r2_rule, STIG-ID|GEN005507-M6, Vuln-ID|V-22460

Plugin: Unix

Control ID: ba4c0f04201d8bf955fa9b4c54a962d49adcc3bfb51f73b929f805eac0f1f048