PHTN-67-000085 - The Photon operating system must configure sshd to disable X11 forwarding.

Information

X11 is an older, insecure graphics forwarding protocol. It is not used by Photon and should be disabled as a general best practice to limit attack surface area and communication channels.

Solution

Open /etc/ssh/sshd_config with a text editor.

Ensure that the 'X11Forwarding' line is uncommented and set to the following:

X11Forwarding no

At the command line, execute the following command:

# service sshd reload

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_VMW_vSphere_6-7_Y23M07_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|II, CCI|CCI-000366, Rule-ID|SV-239156r675276_rule, STIG-ID|PHTN-67-000085, Vuln-ID|V-239156

Plugin: Unix

Control ID: fd46707ddb154695b556e068feba22226c7c4a105901dc18468d4d2cb31cf8c1