GEN005522 - The SSH public host key files must have mode 0644 or less permissive.

Information

If a public host key file is modified by an unauthorized user, the SSH service may be compromised.

Solution

Change the permissions for the SSH public host key files.
# chmod 0644 /etc/ssh/*key.pub

See Also

http://iasecontent.disa.mil/stigs/zip/U_RedHat_5_V1R18_STIG.zip

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-6, CAT|II, CCI|CCI-000225, Group-ID|V-22471, Rule-ID|SV-37844r1_rule, STIG-ID|GEN005522, Vuln-ID|V-22471

Plugin: Unix

Control ID: 52562e2f1997392243afd2a708cc7fdac845cec756348b1a55b7e12969cb7b50