ESXI-06-000015 - The SSH daemon must not allow authentication using an empty password.

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Configuring this setting for the SSH daemon provides additional assurance that remote login via SSH will require a password, even in the event of misconfiguration elsewhere.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

To explicitly disallow remote login from accounts with empty passwords, add or correct the following line in '/etc/ssh/sshd_config':

PermitEmptyPasswords no

See Also

http://iasecontent.disa.mil/stigs/zip/U_VMware_vSphere_6-0_ESXi_V1R4_STIG.zip

Item Details

References: CAT|I, CCI|CCI-000366, Group-ID|V-63199, Rule-ID|SV-77689r1_rule, STIG-ID|ESXI-06-000015

Plugin: VMware

Control ID: e421695f59e0c56c8c2cf57c28a2b7ee9f6e8b067eb693770fd4202a088cd81e