1.230 RHEL-09-255140

Information

RHEL 9 SSH daemon must not allow Kerberos authentication.

GROUP ID: V-258004
RULE ID: SV-258004r1045067

Kerberos authentication for SSH is often implemented using Generic Security Service Application Program Interface (GSSAPI). If Kerberos is enabled through SSH, the SSH daemon provides a means of access to the system's Kerberos implementation. Vulnerabilities in the system's Kerberos implementations may be subject to exploitation.

Satisfies: SRG-OS-000364-GPOS-00151, SRG-OS-000480-GPOS-00227

Solution

Configure the SSH daemon to not allow Kerberos authentication.

Add the following line in "/etc/ssh/sshd_config" or to a file in "/etc/ssh/sshd_config.d", or uncomment the line and set the value to "no":

KerberosAuthentication no

The SSH service must be restarted for changes to take effect:

$ sudo systemctl restart sshd.service

See Also

https://workbench.cisecurity.org/benchmarks/22008