Information
The HostbasedAuthentication parameter specifies if authentication is allowed through trusted hosts via the user of .rhosts, or /etc/hosts.equiv, along with successful public key client host authentication.
More information about the openSSH server configuration is available in the "Configure SSH Server" section overview.
Even though the .rhosts files are ineffective if support is disabled in /etc/pam.conf, disabling the ability to use .rhosts files in SSH provides an additional layer of protection.
Solution
Edit the /etc/ssh/sshd_config file to set the HostbasedAuthentication parameter to no above any Match entries as follows:
HostbasedAuthentication no