5.3.37 Ensure no 'shosts.equiv' files exist on the system - shosts.equiv files exist on the system

Information

The operating system must not contain shosts.equiv files.

Rationale:

The shosts.equiv files are used to configure host-based authentication for the system via SSH. Host-based authentication is not sufficient for preventing unauthorized access to the system, as it does not require interactive identification and authentication of a connection request, or for the use of two-factor authentication.

Solution

Remove any found shosts.equiv files from the system.
Refer to the list found in the Audit section and apply the path to the file in the example below:

# rm /[path]/[to]/[file]/shosts.equiv

See Also

https://workbench.cisecurity.org/files/3636

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CCI|CCI-000366, CSCv6|9.1, Rule-ID|SV-204607r603261_rule, STIG-ID|RHEL-07-040550

Plugin: Unix

Control ID: 915029e8457164c5b311b11fe4ae1a7f7b7743397a878374017093310fedcece