PHTN-67-000119 - The Photon operating system must protect sshd configuration from unauthorized access.

Information

The sshd_config file contains all the configuration items for sshd. Incorrect or malicious configuration of sshd can allow unauthorized access to the system, insecure communication, limited forensic trail, etc.

Solution

At the command line, execute the following commands:

# chmod 600 /etc/ssh/sshd_config
# chown root:root /etc/ssh/sshd_config

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_VMW_vSphere_6-7_Y23M07_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|II, CCI|CCI-000366, Rule-ID|SV-239190r675378_rule, STIG-ID|PHTN-67-000119, Vuln-ID|V-239190

Plugin: Unix

Control ID: 39d8df5a6272299e26d3920d18e7a4521ba52b9e2a17844439daa815f98acf20