STIGQter STIGQter: STIG Summary: Tri-Lab Operating System Stack (TOSS) 5 Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 26 Mar 2026:

The TOSS 5 SSH server must be configured to use only Message Authentication Codes (MACs) employing FIPS 140-3-validated cryptographic hash algorithms.

DISA Rule

SV-282525r1201367_rule

Vulnerability Number

V-282525

Group Title

SRG-OS-000250-GPOS-00093

Rule Version

TOSS-05-000244

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the TOSS 5 SSH server to use only MACs employing FIPS 140-3-approved algorithms by updating the "/etc/crypto-policies/back-ends/openssh.config" file with the following line:

MACs hmac-sha2-256-etm@openssh.com,hmac-sha1-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha1,umac-128@openssh.com,hmac-sha2-512

Restart the system for the changes to take effect.

Check Contents

Verify SSH server is configured to use only ciphers employing FIPS 140-3-approved algorithms using the following command:

$ sudo grep -i macs /etc/crypto-policies/back-ends/openssh.config
MACs hmac-sha2-256-etm@openssh.com,hmac-sha1-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha1,umac-128@openssh.com,hmac-sha2-512

If the MACs entries in the "openssh.config" file have any hashes other than "hmac-sha2-256-etm@openssh.com", "hmac-sha2-256", "hmac-sha2-512-etm@openssh.com", "hmac-sha2-512"; the order differs from the example above; they are missing; or commented out, this is a finding.

Vulnerability Number

V-282525

Documentable

False

Rule Version

TOSS-05-000244

Severity Override Guidance

Verify SSH server is configured to use only ciphers employing FIPS 140-3-approved algorithms using the following command:

$ sudo grep -i macs /etc/crypto-policies/back-ends/openssh.config
MACs hmac-sha2-256-etm@openssh.com,hmac-sha1-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha1,umac-128@openssh.com,hmac-sha2-512

If the MACs entries in the "openssh.config" file have any hashes other than "hmac-sha2-256-etm@openssh.com", "hmac-sha2-256", "hmac-sha2-512-etm@openssh.com", "hmac-sha2-512"; the order differs from the example above; they are missing; or commented out, this is a finding.

Check Content Reference

M

Target Key

5738