PHTN-30-000078 - The Photon operating system must configure sshd to disallow Generic Security Service Application Program Interface (GSSAPI) authentication.

Information

GSSAPI authentication is used to provide additional authentication mechanisms to applications. Allowing GSSAPI authentication through Secure Shell (SSH) exposes the system's GSSAPI to remote hosts, increasing the attack surface of the system.

Solution

Navigate to and open:

/etc/ssh/sshd_config

Ensure the 'GSSAPIAuthentication' line is uncommented and set to the following:

GSSAPIAuthentication no

At the command line, run the following command:

# systemctl restart sshd.service

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_VMW_vSphere_7-0_Y24M01_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|II, CCI|CCI-000366, Rule-ID|SV-256547r887315_rule, STIG-ID|PHTN-30-000078, Vuln-ID|V-256547

Plugin: Unix

Control ID: 79229b2cb815bd0afbf7a7a3f8a7c39720b2f044288bf4b3c2b1947c5c589fc6