Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

hmac-ripemd160 no longer available on openssh 7.6 and newer (2017+) #8212

Closed
msmeissn opened this issue Feb 13, 2022 · 3 comments · Fixed by #10739
Closed

hmac-ripemd160 no longer available on openssh 7.6 and newer (2017+) #8212

msmeissn opened this issue Feb 13, 2022 · 3 comments · Fixed by #10739
Labels
SLES SUSE Linux Enterprise Server product related. Ubuntu Ubuntu product related.

Comments

@msmeissn
Copy link
Contributor

Description of problem:

linux_os/guide/services/ssh/ssh_server/sshd_use_strong_macs remediation tries to inject a "hmac-ripemd160" hmac.

this is not available on SLES 15.

It was removed with openssh 7.6 upstream in 2017, so it probably can go away here too.
https://www.openssh.com/txt/release-7.6

SCAP Security Guide Version:

0.1.60

Operating System Version:

SUSE Linux Enterprise Server 15 SP2

Steps to Reproduce:

  1. run cis bash remediaton
  2. restart sshd

Actual Results:

sshd no longer starts, complains about "MACs [email protected],[email protected],[email protected],hmac-sha2-512,hmac-sha2-256,hmac-ripemd160" line

Expected Results:

sshd starts

Additional Information/Debugging Steps:

@msmeissn msmeissn changed the title hmac-ripemd160 no longer available on SLES 15 SP2 hmac-ripemd160 no longer available on openssh 7.6 and newer (2017+) Feb 13, 2022
@marcusburghardt marcusburghardt added the SLES SUSE Linux Enterprise Server product related. label Sep 6, 2022
@thedarave
Copy link

This is not available on Ubuntu 22.04 either. Bug encountered in version 0.1.68 at the same point. This prevents SSHD from starting. Recommend checking sshd_config.5 man file for valid ciphers, algorithms, and MACs as part of the automatic fix.

@marcusburghardt
Copy link
Member

FYI @dodys

@marcusburghardt marcusburghardt added the Ubuntu Ubuntu product related. label Aug 8, 2023
@dodys
Copy link
Contributor

dodys commented Aug 8, 2023

This is being addressed in #10739

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
SLES SUSE Linux Enterprise Server product related. Ubuntu Ubuntu product related.
Projects
None yet
Development

Successfully merging a pull request may close this issue.

4 participants