GEN000452 - The system must display the date and time of the last successful account login upon login.

Information

Providing users with feedback on when account accesses last occurred facilitates user recognition and reporting of unauthorized account use.

Solution

Configure the system to display the date and time of the last successful login upon logging in. Consult OS documentation for the configuration procedure.
Enable PrintLastLog in the SSH daemon. To enable PrintLastLog in the SSH daemon, remove any comment disabling this option from /etc/ssh/sshd_config. The line should look like: 'PrintLastLog yes'.
Restart sshd.
# kill -1 <PID of sshd>

See Also

http://iasecontent.disa.mil/stigs/zip/U_STIG_Library_2015_07.zip

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-9, CAT|III, CCI|CCI-000052, Rule-ID|SV-39095r1_rule, STIG-ID|GEN000452, Vuln-ID|V-22299

Plugin: Unix

Control ID: 77cea0a3f8ec545e47364f8fa63642e9a1490d4071517d5540ab846e99959d76