5.3.14 Ensure SSH PermitUserEnvironment is disabled

Information

The PermitUserEnvironment option allows users to present environment options to the ssh daemon.

Rationale:

Permitting users the ability to set environment variables through the SSH daemon could potentially allow users to bypass security controls (e.g. setting an execution path that has ssh executing a Trojan's programs)

Solution

Edit the /etc/ssh/sshd_config file to set the parameter as follows:

PermitUserEnvironment no

Default Value:

PermitUserEnvironment no

See Also

https://workbench.cisecurity.org/files/3636

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CCI|CCI-000366, CSCv7|5.1, Rule-ID|SV-204434r603261_rule, STIG-ID|RHEL-07-010460

Plugin: Unix

Control ID: 2f8a39de3e7e840fc61dfc8478054b332586e59f7d710ba3d1b4b4edb0ced95b