AIX7-00-002110 - AIX must setup SSH daemon to disable revoked public keys.

Information

Without configuring a local cache of revocation data, there is the potential to allow access to users who are no longer authorized (users with revoked certificates).

Solution

Obtain the file that contains all the public keys that need to be revoked from ISSO/SA and save the file in /etc/ssh/ directory.

Edit the '/etc/ssh/sshd_config' file to allow 'RevokedKeys' to point to the revoked key file obtained above.

Restart the SSH daemon:
# stopsrc -s sshd
# startsrc -s sshd

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_IBM_AIX_7-x_V3R1_STIG.zip

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-5(2)(d), CAT|II, CCI|CCI-001991, CCI|CCI-004068, Rule-ID|SV-215293r1009549_rule, STIG-ID|AIX7-00-002110, STIG-Legacy|SV-101647, STIG-Legacy|V-91549, Vuln-ID|V-215293

Plugin: Unix

Control ID: 8957fd32d47383afad13c753c9c2296ccf7312f57c41276e5f6eddf83f6b988c