5.2.11 Ensure sshd IgnoreRhosts is enabled

Information

The IgnoreRhosts parameter specifies that .rhosts and .shosts files will not be used in RhostsRSAAuthentication or HostbasedAuthentication.

More information about the openSSH server configuration is available in the "Configure SSH Server" section overview.

Setting this parameter forces users to enter a password when authenticating with SSH.

Solution

Edit the /etc/ssh/sshd_config file to set the IgnoreRhosts parameter to yes as follows:

IgnoreRhosts yes

See Also

https://workbench.cisecurity.org/benchmarks/25279

Item Details

Category: CONFIGURATION MANAGEMENT, IDENTIFICATION AND AUTHENTICATION

References: 800-53|CM-1, 800-53|CM-2, 800-53|CM-6, 800-53|CM-7, 800-53|IA-5, 800-53|IA-5(1), CSCv7|4.4

Plugin: Unix

Control ID: 0857b29a00544a50c58edfcecc3d8d78a5379fd2dfe584b4f510afd195650e13