ip ssh message-authentication-code

Configures one or more message authentication code used for data integrity over the SSH connection.
Syntax
ip ssh message-authentication-code [ hmac-sha2-256 | hmac-sha2-512 | hmac-sha1 | algorithm_reference | . . . ]
no ip ssh message-authentication-code [ hmac-sha2-256 | hmac-sha2-512 | hmac-sha1 | algorithm_reference | . . . ]
Command Default

By default all the below message-authentication codes are supported.

Parameters
hmac-sha2-256
Hash-based Message Authentication Code (HMAC) Secure Hash Algorithm2 (SHA2) 256-bit authentication algorithm
hmac-sha2-512
Hash-based Message Authentication Code (HMAC) Secure Hash Algorithm2 (SHA2) 512-bit authentication algorithm
hmac-sha1
Hash-based Message Authentication Code (HMAC) Secure Hash Algorithm1 (SHA1)
algorithm_reference
Provides a linked cross-reference to one of the following supported Open SSH authentication algorithms.
umac-64-etm@openssh.com
The Universal-hash Message Authentication Code UMAC-64 Encrypt-then-MAC option
umac-128-etm@openssh.com
The Universal-hash Message Authentication Code UMAC-128 Encrypt-then-MAC option
hmac-sha2-256-etm@openssh.com
The Hash-based Message Authentication Code (HMAC) Secure Hash Algorithm 256-bit (SHA-256) Encrypt-then-MAC option
hmac-sha2-512-etm@openssh.com
The Hash-based Message Authentication Code (HMAC) Secure Hash Algorithm 512-bit (SHA-512) Encrypt-then-MAC option
hmac-sha1-etm@openssh.com
The Hash-based Message Authentication Code (HMAC) Secure Hash Algorithm1 (SHA1) Encrypt-then-MAC option
umac-64@openssh.com
The Universal-hash Message Authentication Code UMAC-64 algorithm
umac-128@openssh.com
The Universal-hash Message Authentication Code UMAC-128 algorithm
Modes

Global configuration mode

Usage Guidelines

Enter algorithms separated by a space.

The no form of the command removes the configured algorithms.

Note: Once you have configured one or more message authentication code algorithm, you can modify them but will not be able to delete the last algorithm. One algorithm must remain configured.

Examples

The following example configures the HMAC SHA2 256 and HMAC SHA2 512 algorithms for SSH communications.

device(config)# ip ssh message-authentication-code  hmac-sha2-256 hmac-sha2-512
device(config)# show running-config | include ip ssh                                
ip ssh message-authentication-code hmac-sha2-512 hmac-sha2-256

The following example removes the HMAC SHA2 512 algorithms for SSH communications.

device(config)# no ip ssh message-authentication-code hmac-sha2-512
device(config)# show running-config | include ip ssh                     
ip ssh message-authentication-code hmac-sha2-256
History
Release version Command history
09.0.10j_cd2, 10.0.10d This command was introduced.