ESXI-06-000016 - The SSH daemon must not permit user environment settings.

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

SSH environment options potentially allow users to bypass access restriction in some configurations.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

To ensure users are not able to present environment options to the SSH daemon, add or correct the following line in '/etc/ssh/sshd_config':

PermitUserEnvironment no

See Also

http://iasecontent.disa.mil/stigs/zip/U_VMware_vSphere_6-0_ESXi_V1R4_STIG.zip

Item Details

References: CAT|II, CCI|CCI-000366, Group-ID|V-63201, Rule-ID|SV-77691r1_rule, STIG-ID|ESXI-06-000016

Plugin: VMware

Control ID: d3d25f4ba1293816450d01d0fb0ee12be4723643531ca369a0c373947c21b6de