GEN005512 M6 - SSH client MACs use FIPS 140-2 approved algorithms - 'MACS configured'

Information

DoD information systems are required to use FIPS 140-2 approved cryptographic hash functions.

Solution

Open a terminal session and edit the SSH client configuration file '/etc/ssh_config' and remove any MACs other than 'hmac-sha1'.

See Also

http://iase.disa.mil/stigs/os/mac/u_mac_osx_10.6_v1r3_stig_20130426.zip

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-13, CAT|II, CCI|CCI-001453, Rule-ID|SV-39376r1_rule, STIG-ID|GEN005512-M6, Vuln-ID|V-22463

Plugin: Unix

Control ID: 7fb4044b04ac7e8ff14034d5fac6e4f16805fd0093520bd27a7a79c9c76d6ccf