GEN005512 - The SSH client must only use MACs employing FIPS 140-2 approved cryptographic hash algorithms

Information

DoD information systems are required to use FIPS 140-2 approved cryptographic hash functions.

Solution

Edit the SSH client configuration and remove any MACs other than hmac-sha1. If necessary, add a MACs line.

See Also

http://iasecontent.disa.mil/stigs/zip/U_STIG_Library_2015_07.zip

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-17(2), CAT|II, CCI|CCI-001453, Rule-ID|SV-26756r1_rule, STIG-ID|GEN005512, Vuln-ID|V-22463

Plugin: Unix

Control ID: 9a138f8ca49c12f8dbbe5ae6266df31e9ac5bc1d14dfce5ad89860efd8aa8230