Skip to content
ATO Pathways
Log In
Overview
Search
Catalogs
SCAP
OSCAL
Catalogs
Profiles
Resources
Documents
Publishers
References
Knowledge Base
Platform Documentation
Compliance Dictionary
Platform Changelog
About
Catalogs
XCCDF
Guide to the Secure Configuration of Ubuntu 20.04
Services
SSH Server
Configure OpenSSH Server if Necessary
Use Only FIPS 140-2 Validated MACs
Use Only FIPS 140-2 Validated MACs
An XCCDF Rule
Details
Profiles
Prose
Use Only FIPS 140-2 Validated MACs
Medium Severity
Limit the MACs to those hash algorithms which are FIPS-approved. The following line in
/etc/ssh/sshd_config
demonstrates use of FIPS-approved MACs:
MACs
If this line does not contain these MACs in exact order, is commented out, or is missing, this is a finding.