How to disable the non etm mac algorithms for SSH, when using system-wide cryptographic policies ?
Issue
-
In the system-wide cryptographic policy, disable below
Non-ETMMAC algorithms for SSH.hmac-sha2-256 umac-128@openssh.com hmac-sha2-512 -
Enable only the
etm( Encrypt then mac) MAC algorithms.hmac-sha2-256-etm@openssh.com umac-128-ethm@openssh.com hmac-sha2-512-etm@openssh.com
Environment
- Red Hat Enterprise Linux 8, 9 and 10
- openssh
- crypto-policies
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.