diff --git a/linux_os/guide/services/ssh/sshd_approved_macs.var b/linux_os/guide/services/ssh/sshd_approved_macs.var index 0a0c972ca3e..dab7237fcb7 100644 --- a/linux_os/guide/services/ssh/sshd_approved_macs.var +++ b/linux_os/guide/services/ssh/sshd_approved_macs.var @@ -14,7 +14,7 @@ options: stig: hmac-sha2-512,hmac-sha2-256 default: hmac-sha2-512,hmac-sha2-256,hmac-sha1,hmac-sha1-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com cis_rhel7: umac-64-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha1-etm@openssh.com,umac-64@openssh.com,umac-128@openssh.com,hmac-sha2-256,hmac-sha2-512,hmac-sha1,hmac-sha1-etm@openssh.com - cis_sle12: umac-64-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha1-etm@openssh.com,umac-64@openssh.com,umac-128@openssh.com,hmac-sha2-256,hmac-sha2-512,hmac-sha1,hmac-sha1-etm@openssh.com - cis_sle15: umac-64-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha1-etm@openssh.com,umac-64@openssh.com,umac-128@openssh.com,hmac-sha2-256,hmac-sha2-512,hmac-sha1,hmac-sha1-etm@openssh.com + cis_sle12: hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256 + cis_sle15: hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256 cis_alinux2: hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256 cis_ubuntu: hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256 diff --git a/products/sle12/profiles/pci-dss-4.profile b/products/sle12/profiles/pci-dss-4.profile index e7c9b9acc5d..1fa1e5e9728 100644 --- a/products/sle12/profiles/pci-dss-4.profile +++ b/products/sle12/profiles/pci-dss-4.profile @@ -77,4 +77,5 @@ selections: - sshd_use_approved_ciphers - sshd_approved_ciphers=cis_sle12 - sshd_use_approved_macs + - sshd_approved_macs=cis_sle12 - sysctl_fs_suid_dumpable diff --git a/products/sle12/profiles/pci-dss.profile b/products/sle12/profiles/pci-dss.profile index 7272d97a177..9285d4417bf 100644 --- a/products/sle12/profiles/pci-dss.profile +++ b/products/sle12/profiles/pci-dss.profile @@ -13,4 +13,5 @@ description: |- selections: - pcidss_3:all:base + - sshd_approved_macs=cis_sle12 - sshd_approved_ciphers=cis_sle12 diff --git a/products/sle15/profiles/pci-dss-4.profile b/products/sle15/profiles/pci-dss-4.profile index 7e1713eb5e6..e6a5ab7b492 100644 --- a/products/sle15/profiles/pci-dss-4.profile +++ b/products/sle15/profiles/pci-dss-4.profile @@ -13,6 +13,7 @@ description: |- selections: - pcidss_4:all:base + - sshd_approved_macs=cis_sle15 - sshd_approved_ciphers=cis_sle15 - '!service_ntp_enabled' - '!service_ntpd_enabled' diff --git a/products/sle15/profiles/pci-dss.profile b/products/sle15/profiles/pci-dss.profile index c4fb4a2a023..f2f7a6fbcbf 100644 --- a/products/sle15/profiles/pci-dss.profile +++ b/products/sle15/profiles/pci-dss.profile @@ -13,4 +13,5 @@ description: |- selections: - pcidss_3:all:base + - sshd_approved_macs=cis_sle15 - sshd_approved_ciphers=cis_sle15