Information
Amazon Linux 2023 SSH daemon must not allow Kerberos authentication.
GROUP ID: V-274045RULE ID: SV-274045r1120123
Kerberos authentication for SSH is often implemented using Generic Security Service Application Program Interface (GSSAPI). If Kerberos is enabled through SSH, the SSH daemon provides a means of access to the system's Kerberos implementation. Vulnerabilities in the system's Kerberos implementations may be subject to exploitation.
Solution
Configure Amazon Linux 2023 so that the SSH daemon does not allow Kerberos authentication.
Add the following line in "/etc/ssh/sshd_config" or to a file in "/etc/ssh/sshd_config.d" or uncomment the line and set the value to "no":
KerberosAuthentication no
The SSH service must be restarted for changes to take effect:
$ sudo systemctl restart sshd.service