Your browser does not allow this site to store cookies and other data. Some functionality on this site may not work without them. See Privacy Policy for details on how we would use cookies.

Tectia

Configuring MACs

The MAC (Message Authentication Code) algorithm(s) used for data integrity verification can be selected in the sshd2_config file:

MACs                hmac-sha1,hmac-md5

The system will attempt to use the different HMAC algorithms in the sequence they are specified on the line. The supported MAC names are the following:

  • hmac-md5

  • hmac-md5-96

  • hmac-sha1

  • hmac-sha1-96

  • hmac-sha256-2@ssh.com

  • hmac-sha224@ssh.com

  • hmac-sha256@ssh.com

  • hmac-sha384@ssh.com

  • hmac-sha512@ssh.com

Special values for this option are the following:

  • Any: allows all the MAC values including none

  • AnyStd: allows only those MACs mentioned in the IETF-SecSh draft (hmac-md5, hmac- md5-96, hmac-sha1, hmac-sha1-96) and none

  • none: means that no cryptographic data integrity method is used

  • AnyMac: the same as Any but excludes none

  • AnyStdMac: the same as AnyStd but exludes none

The default MAC algorithms are:

  • hmac-sha1

  • hmac-sha1-96

  • hmac-sha256-2@ssh.com

  • hmac-sha224@ssh.com

  • hmac-sha256@ssh.com

  • hmac-sha384@ssh.com

  • hmac-sha512@ssh.com

===AUTO_SCHEMA_MARKUP===