AIX7-00-002124 - If AIX SSH daemon is required, the SSH daemon must only listen on the approved listening IP addresses.

Information

The SSH daemon should only listen on the approved listening IP addresses. Otherwise the SSH service could be subject to unauthorized access.

Solution

Edit the SSH daemon config file and add/modify the 'ListenAddress' network addresses:
# vi /etc/ssh/sshd_config

Restart SSH daemon:
# stopsrc -s sshd
# startsrc -s sshd

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_IBM_AIX_7-x_V3R1_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|II, CCI|CCI-000366, Rule-ID|SV-215306r991593_rule, STIG-ID|AIX7-00-002124, STIG-Legacy|SV-101871, STIG-Legacy|V-91773, Vuln-ID|V-215306

Plugin: Unix

Control ID: 24024159aaa3f190d01067f2b310a681c4839693c71f28f1adc6b931ad70922a