6.2.14 Set SSH Banner - Banner /etc/issue

Information

The Banner parameter specifies a file whose contents must be sent to the remote user before authentication is permitted. By default, no banner is displayed.

Rationale:

Banners are used to warn connecting users of the particular site's policy regarding connection. Consult with your legal department for the appropriate warning banner for your site.

Solution

Edit the /etc/ssh/sshd_config file to set the parameter as follows:

Banner /etc/issue.net

Default Value:

OS Default: No

See Also

https://workbench.cisecurity.org/files/3096

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, CSCv7|5.1

Plugin: Unix

Control ID: f4f0c53e3a4b8f7ef4d406677383f6eb9830faa1cacccbd745496516c5dc409d