Information
Operating systems using encryption are required to use FIPS-compliant mechanisms for authenticating to macOS.
For OpenSSH to utilize the Apple Corecrypto FIPS-validated algorithms, a specific configuration is required to leverage the shim implemented by macOS to bypass the non-FIPS validated LibreSSL crypto module packaged with OpenSSH. Information regarding this configuration can be found in the manual page 'apple_ssh_and_fips'.
Satisfies: SRG-OS-000033-GPOS-00014, SRG-OS-000120-GPOS-00061, SRG-OS-000125-GPOS-00065, SRG-OS-000250-GPOS-00093, SRG-OS-000393-GPOS-00173, SRG-OS-000394-GPOS-00175
Solution
Configure the macOS system to use approved SSH MACs by creating a plain text file in the /private/etc/ssh/ssh_config.d/ directory containing the following:
MACs hmac-sha2-256
The SSH service must be restarted for changes to take effect.
Item Details
Category: ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, MAINTENANCE
References: 800-53|AC-17(2), 800-53|IA-7, 800-53|MA-4(6), 800-53|MA-4c., CAT|I, CCI|CCI-000068, CCI|CCI-000803, CCI|CCI-000877, CCI|CCI-001453, CCI|CCI-002890, CCI|CCI-003123, Rule-ID|SV-257774r958408_rule, STIG-ID|APPL-12-000058, Vuln-ID|V-257774
Control ID: 83355617e39e3a67cefa88c7edbfe36227a8892fa9118fd1b7e631756e674aac