6.1.11 Set SSH Banner - Check if Banner is not commented and set to /etc/issue for the server

Information

The Banner parameter specifies a file whose contents must sent to the remote user before authentication is permitted. By default, no banner is displayed.

Note - If you will be editing all the SSH parameters, use the script in section 6.1 Configure SSH.

Solution

Edit the /etc/ssh/sshd_config file to set the parameter as follows-
awk '/^#Banner/ { $1 = 'Banner' } { print }' /etc/ssh/sshd_config > /etc/ssh/sshd_config.new
/usr/bin/mv /etc/ssh/sshd_config.new /etc/ssh/sshd_config
/usr/sbin/pkgchk -f -n -p /etc/ssh/sshd_config
/usr/sbin/svcadm restart svc:/network/ssh

See Also

https://workbench.cisecurity.org/files/614

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-8a.

Plugin: Unix

Control ID: e5e914efc6ee42ab1d65b20e9e6b0659c884ea9f7abb15fad8c209322a500dba