Loading
View Categories

How do I configure SSH MAC algorithms in ProVide?

MAC (Message Authentication Code) algorithms are what ProVide’s SFTP (SSH) server uses to verify the integrity of each message, confirming data hasn’t been tampered with in transit. ProVide’s default MAC algorithms are HMAC-SHA1, HMAC-SHA1-96, HMAC-MD5, HMAC-MD5-96, HMAC-SHA256, HMAC-SHA256-96, HMAC-SHA2-256, HMAC-SHA2-512, AES128-GCM, and AES256-GCM. You change which are offered by editing the [SFTP MAC Algorithms] section of the Settings.ini configuration file.

How to change the MAC algorithms #

  1. Back up your Settings.ini file first.
  2. Stop the ProVide service (changes to Settings.ini are applied on startup).
  3. Open Settings.ini and edit the [SFTP MAC Algorithms] section to list the algorithms you want to allow, in order of preference.
  4. Save the file and restart the ProVide service.

During each connection, ProVide and the client agree on the first MAC algorithm they both support, so the order and the set you list determine what actually gets used.

Available MAC algorithms #

The following algorithms are available for use in ProVide, listed under [SFTP MAC Algorithms] in Settings.ini:

[SFTP MAC Algorithms]
HMAC-SHA1
HMAC-SHA1-96
HMAC-MD5
HMAC-MD5-96
NONE
HMAC-RIPEMD160
HMAC-RIPEMD
HMAC-RIPEMD-OPENSSH
HMAC-SHA256
HMAC-SHA256-96
UMAC32
UMAC64
UMAC96
UMAC128
HMAC-SHA2-256
HMAC-SHA2-512
AES128-GCM
AES256-GCM
POLY1305
SHA2-256-ETM
SHA2-512-ETM

List only the algorithms you want to allow, keeping your preferred (strongest) options at the top.

Security note #

To harden your server, favour strong modern options such as the encrypt-then-MAC variants (SHA2-256-ETM, SHA2-512-ETM), the AES-GCM and POLY1305 authenticated modes, and HMAC-SHA2-256 / HMAC-SHA2-512. Drop the weak legacy entries where your clients allow it: HMAC-MD5, HMAC-MD5-96, and the SHA-1 and RIPEMD variants are considered weak, and NONE disables integrity checking entirely and should never be used in production. Always test with your actual SFTP clients after editing the list, because if the server and a client share no common MAC algorithm, that client won’t be able to connect.

YOUR CART

CUSTOMERS ALSO ADD

HAVE A COUPON?
ORDER SUMMARY
We'll send a tailored quote to your inbox.

The invoice will be e-mailed once your order is confirmed.

ProVide Server

Your cart is empty

maxi_provideserver

Choose your version of ProVide Server to download

For the ultimate experience of ProVide’s features and functions,
we recommend choosing the MAXI License.

Follow the 3 easy steps below to install ProVide Server
  1. Download the version you need using the buttons below.
  2. Get a free MAXI trial license by clicking the “Get Maxi Trial License” button and enter your email. The license key will be sent to your email.
  3. Activate the license key by following this simple step-by-step-guide.

Free Trial

Get
ProVide Software