3.6.1.8 Configuring SSH - removal of /etc/shosts.equiv

Information

The recommendation is to remove the /etc/shosts.equiv file.

Rationale:

The existence of a /etc/shosts.equiv file, combined with the correct SSH parameter can allow passwordless authentication between servers. As previous recommendations in this section disable this authentication method these files, if they exist, should be removed.

Solution

Review the content of the /etc/shosts.equiv file:

cat /etc/shosts.equiv

If the file exists:

rm /etc/shosts.equiv

Default Value:

N/A

Additional Information:

Reversion:

The /etc/shosts.equiv file would need to be restored from a backup.

See Also

https://workbench.cisecurity.org/files/4119

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, 800-53|CM-7, CSCv7|9.2

Plugin: Unix

Control ID: bd7cd14646596f42f78fb0c373dd1c0e4c6dd33ef8b2cc23b1f6564c308b4d21