SV-275625r1147925_rule
V-275625
SRG-OS-000250-GPOS-00093
RIIM-OS-255055
CAT I
10
Configure the SSH server to only use MACs that employ FIPS 140-2/140-3-approved hashes.
Add or modify the following line in the "/etc/ssh/sshd_config" file:
MACs hmac-sha2-512,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-256-etm@openssh.com
Restart the SSH server for the changes to take effect:
$ sudo systemctl reload sshd.service
Verify the SSH server is configured to only use MACs that employ FIPS 140-2/140-3-approved ciphers by using the following command:
$ sudo /usr/sbin/sshd -dd 2>&1 | awk '/filename/ {print $4}' | tr -d '\r' | tr '\n' ' ' | xargs sudo grep -iH 'macs'
/etc/ssh/sshd_config:MACs hmac-sha2-512,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-256-etm@openssh.com
If "MACs" does not contain only the hashes "hmac-sha2-512,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-256-etm@openssh.com" in exact order, is commented out, is missing, or conflicting results are returned, this is a finding.
V-275625
False
RIIM-OS-255055
Verify the SSH server is configured to only use MACs that employ FIPS 140-2/140-3-approved ciphers by using the following command:
$ sudo /usr/sbin/sshd -dd 2>&1 | awk '/filename/ {print $4}' | tr -d '\r' | tr '\n' ' ' | xargs sudo grep -iH 'macs'
/etc/ssh/sshd_config:MACs hmac-sha2-512,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-256-etm@openssh.com
If "MACs" does not contain only the hashes "hmac-sha2-512,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-256-etm@openssh.com" in exact order, is commented out, is missing, or conflicting results are returned, this is a finding.
M
5706