Skip to content

Commit 7708eb8

Browse files
authored
Merge pull request #12735 from ericeberry/u2404_5115
Ubuntu 24.04 5.1.15 Ensure sshd MACs are configured
2 parents ff8de8b + 4b69610 commit 7708eb8

File tree

4 files changed

+5
-5
lines changed

4 files changed

+5
-5
lines changed

controls/cis_ubuntu2404.yml

Lines changed: 2 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1687,11 +1687,10 @@ controls:
16871687
levels:
16881688
- l1_server
16891689
- l1_workstation
1690-
related_rules:
1690+
rules:
16911691
- sshd_strong_macs=cis_ubuntu2404
16921692
- sshd_use_strong_macs
1693-
status: planned
1694-
notes: TODO. Partial/incorrect implementation exists.See related rules. Analogous to ubuntu2204/5.2.14.
1693+
status: automated
16951694

16961695
- id: 5.1.16
16971696
title: Ensure sshd MaxAuthTries is configured (Automated)

linux_os/guide/services/ssh/ssh_server/sshd_use_strong_macs/tests/good_mac.pass.sh

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,4 @@
1-
# platform = multi_platform_fedora,multi_platform_ol,multi_platform_rhel
1+
# platform = multi_platform_fedora,multi_platform_ol,multi_platform_rhel,multi_platform_ubuntu
22

33
sed -i 's/^\s*MACs\s.*//i' /etc/ssh/sshd_config
44
echo "MACs hmac-sha2-512" >> /etc/ssh/sshd_config
Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,3 @@
1-
# platform = multi_platform_fedora,multi_platform_ol,multi_platform_rhel
1+
# platform = multi_platform_fedora,multi_platform_ol,multi_platform_rhel,multi_platform_ubuntu
22

33
sed -i 's/^\s*MACs\s/# &/i' /etc/ssh/sshd_config

linux_os/guide/services/ssh/sshd_strong_macs.var

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -17,3 +17,4 @@ options:
1717
cis_sle12: [email protected],[email protected],[email protected],hmac-sha2-512,hmac-sha2-256,hmac-ripemd160
1818
cis_sle15: [email protected],[email protected],[email protected],hmac-sha2-512,hmac-sha2-256
1919
cis_ubuntu2204: [email protected],[email protected],[email protected],hmac-sha2-512,hmac-sha2-256
20+

0 commit comments

Comments
 (0)