4.7.3.5 Ensure sshd Banner is configured

Information

The Banner parameter specifies a file whose contents must be sent to the remote user before authentication is permitted. By default, no banner is displayed.

Banners are used to warn connecting users of the particular site's policy regarding connection. Presenting a warning message prior to the normal user login may assist the prosecution of trespassers on the computer system.

Solution

Edit the /etc/ssh/sshd_config file to set the parameter above any Match set entries as follows:

Banner /etc/ssh/ssh_banner

Re-cycle the sshd daemon to pick up the configuration changes:

stopsrc -s sshd
startsrc -s sshd

Note: First occurrence of a option takes precedence, Match set statements withstanding.

Edit the file being called by the Banner argument with the appropriate contents according to your site policy.

See Also

https://workbench.cisecurity.org/benchmarks/10385

Item Details

Category: CONFIGURATION MANAGEMENT, MAINTENANCE

References: 800-53|CM-7, 800-53|MA-4, CSCv7|9.2

Plugin: Unix

Control ID: 723f77df3971408c74073c1bc4778542ee1b2a30dfae08dbd6761e3e783b304b