1.230 RHEL-09-255140

Information

RHEL 9 SSH daemon must not allow Kerberos authentication.

GROUP ID: V-258004
RULE ID: SV-258004r1045067

Kerberos authentication for SSH is often implemented using Generic Security Service Application Program Interface (GSSAPI). If Kerberos is enabled through SSH, the SSH daemon provides a means of access to the system's Kerberos implementation. Vulnerabilities in the system's Kerberos implementations may be subject to exploitation.

Satisfies: SRG-OS-000364-GPOS-00151, SRG-OS-000480-GPOS-00227

Solution

Configure the SSH daemon to not allow Kerberos authentication.

Add the following line in "/etc/ssh/sshd_config" or to a file in "/etc/ssh/sshd_config.d", or uncomment the line and set the value to "no":

KerberosAuthentication no

The SSH service must be restarted for changes to take effect:

$ sudo systemctl restart sshd.service

See Also

https://workbench.cisecurity.org/benchmarks/22008

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-5(1), CAT|II, CCI|CCI-001813, Rule-ID|SV-258004r1045067_rule, STIG-ID|RHEL-09-255140, Vuln-ID|V-258004

Plugin: Unix

Control ID: bd70e8c6f1320d45014e9ed9595eafda5c9a78fa3cbe3e9ee1f4b3b6d7c861ec