Information
OL 9 SSH daemon must not allow Kerberos authentication.
GROUP ID: V-271718
RULE ID: SV-271718r1091866
Kerberos authentication for SSH is often implemented using Generic Security Service Application Program Interface (GSSAPI). If Kerberos is enabled through SSH, the SSH daemon provides a means of access to the system's Kerberos implementation. Vulnerabilities in the system's Kerberos implementations may be subject to exploitation.
Solution
Configure the SSH daemon to not allow Kerberos authentication.
Add the following line in "/etc/ssh/sshd_config" or to a file in "/etc/ssh/sshd_config.d" or uncomment the line and set the value to "no":
KerberosAuthentication no
The SSH service must be restarted for changes to take effect:
$ sudo systemctl restart sshd.service