GEN005522 - The SSH public host key files must have mode 0644 or less permissive.

Information

If a public host key file is modified by an unauthorized user, the SSH service may be compromised.

Solution

Change the permissions for the SSH public host key files.
# chmod 0644 /etc/ssh/*key.pub

See Also

http://iasecontent.disa.mil/stigs/zip/U_STIG_Library_2015_07.zip

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-6, CAT|II, CCI|CCI-000225, Rule-ID|SV-26764r1_rule, STIG-ID|GEN005522, Vuln-ID|V-22471

Plugin: Unix

Control ID: 10270aceb8248e4ddcdffa56cb4e01b0e72b1c575d5c3bb34b2af394a17504eb