SV-282525r1201367_rule
V-282525
SRG-OS-000250-GPOS-00093
TOSS-05-000244
CAT II
10
Configure the TOSS 5 SSH server to use only MACs employing FIPS 140-3-approved algorithms by updating the "/etc/crypto-policies/back-ends/openssh.config" file with the following line:
MACs hmac-sha2-256-etm@openssh.com,hmac-sha1-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha1,umac-128@openssh.com,hmac-sha2-512
Restart the system for the changes to take effect.
Verify SSH server is configured to use only ciphers employing FIPS 140-3-approved algorithms using the following command:
$ sudo grep -i macs /etc/crypto-policies/back-ends/openssh.config
MACs hmac-sha2-256-etm@openssh.com,hmac-sha1-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha1,umac-128@openssh.com,hmac-sha2-512
If the MACs entries in the "openssh.config" file have any hashes other than "hmac-sha2-256-etm@openssh.com", "hmac-sha2-256", "hmac-sha2-512-etm@openssh.com", "hmac-sha2-512"; the order differs from the example above; they are missing; or commented out, this is a finding.
V-282525
False
TOSS-05-000244
Verify SSH server is configured to use only ciphers employing FIPS 140-3-approved algorithms using the following command:
$ sudo grep -i macs /etc/crypto-policies/back-ends/openssh.config
MACs hmac-sha2-256-etm@openssh.com,hmac-sha1-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha1,umac-128@openssh.com,hmac-sha2-512
If the MACs entries in the "openssh.config" file have any hashes other than "hmac-sha2-256-etm@openssh.com", "hmac-sha2-256", "hmac-sha2-512-etm@openssh.com", "hmac-sha2-512"; the order differs from the example above; they are missing; or commented out, this is a finding.
M
5738