Information
RHEL 9 SSH daemon must not allow Kerberos authentication.
GROUP ID: V-258004
RULE ID: SV-258004r1045067
Kerberos authentication for SSH is often implemented using Generic Security Service Application Program Interface (GSSAPI). If Kerberos is enabled through SSH, the SSH daemon provides a means of access to the system's Kerberos implementation. Vulnerabilities in the system's Kerberos implementations may be subject to exploitation.
Satisfies: SRG-OS-000364-GPOS-00151, SRG-OS-000480-GPOS-00227
Solution
Configure the SSH daemon to not allow Kerberos authentication.
Add the following line in "/etc/ssh/sshd_config" or to a file in "/etc/ssh/sshd_config.d", or uncomment the line and set the value to "no":
KerberosAuthentication no
The SSH service must be restarted for changes to take effect:
$ sudo systemctl restart sshd.service