APPL-11-000052 - The macOS system must be configured with the SSH daemon ClientAliveCountMax option set to 0.

Information

If SSH is not being used, this is Not Applicable.

The SSH daemon 'ClientAliveCountMax' option must be set correctly. To verify the SSH idle timeout will occur when the 'ClientAliveCountMax' is set, run the following command:

/usr/bin/grep ^ClientAliveCountMax /etc/ssh/sshd_config

If the setting is not 'ClientAliveCountMax 0', this is a finding.

Solution

To ensure that the SSH idle timeout occurs precisely when the 'ClientAliveCountMax' is set, run the following command:

/usr/bin/sudo /usr/bin/sed -i.bak 's/.*ClientAliveCountMax.*/ClientAliveCountMax 0/' /etc/ssh/sshd_config

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Apple_macOS_11_V1R1_STIG.zip

Item Details

References: CAT|II, CCI|CCI-001133, Rule-ID|SV-230765r599842_rule, STIG-ID|APPL-11-000052, Vuln-ID|V-230765

Plugin: Unix

Control ID: 16dda3ad0cc9a19f75264c26296f8768c479344b7b001233ba272d07dfe65371