GEN002100 - The .rhosts file must not be supported in PAM.

Information

The .rhosts files are used to specify a list of hosts permitted remote access to a particular account without authenticating. The use of such a mechanism defeats strong identification and authentication requirements.

Solution

Edit /etc/pam.conf and remove the reference(s) to the rhosts_auth module.

See Also

http://iasecontent.disa.mil/stigs/zip/U_STIG_Library_2015_07.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|II, CCI|CCI-000366, Rule-ID|SV-38845r1_rule, STIG-ID|GEN002100, Vuln-ID|V-11989

Plugin: Unix

Control ID: e5087c54852d99fee8b5d70dca6c8d62aec6274e7f3d8f0e6f5934c80fa55784