4.7.2.10 /etc/ssh/ssh_config

Information

The /etc/ssh/ssh_config file defines SSH client behavior.

Rationale:

The /etc/ssh/ssh_config file is the system-wide client configuration file for OpenSSH, which allows you to set options that modify the operation of the client programs. The recommended value is not to provide any writable access rights for any user other than root.

Solution

Change the permissions of the /etc/ssh/ssh_config file to ensure that only the owner can read and write to the file:

chmod 644 /etc/ssh/ssh_config

Default Value:

640

Additional Information:

Using the octal mode to (re)set the mode will also disable any ACL's that might have been set.

See Also

https://workbench.cisecurity.org/benchmarks/13069

Item Details

Category: CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

References: 800-53|CM-2, 800-53|CM-6, 800-53|CM-7, 800-53|CM-7(1), 800-53|CM-9, 800-53|SA-3, 800-53|SA-8, 800-53|SA-10, CSCv7|5.1

Plugin: Unix

Control ID: 35deedb90e237d5aeda78dfa40b6c39ea041403d5fba1d27bf5a152d844aa050