5.1.11 Ensure sshd IgnoreRhosts is enabled

Information

The IgnoreRhosts parameter specifies that .rhosts and .shosts files will not be used in RhostsRSAAuthentication or HostbasedAuthentication.

More information about the openSSH server configuration is available in the "Configure SSH Server" section overview.

Setting this parameter forces users to enter a password when authenticating with SSH.

Solution

Create or edit a *.conf file in the /etc/ssh/sshd_config.d/ directory to set the IgnoreRhosts parameter to yes above any Include entry as follows:

IgnoreRhosts yes

See Also

https://workbench.cisecurity.org/benchmarks/26236

Item Details

Category: CONFIGURATION MANAGEMENT, IDENTIFICATION AND AUTHENTICATION

References: 800-53|CM-1, 800-53|CM-2, 800-53|CM-6, 800-53|CM-7, 800-53|IA-5, 800-53|IA-5(1), CSCv7|4.4

Plugin: Unix

Control ID: ea16a3cf25255dc95bf12543c3e29f196aa4cc0f0c345e39a24531cf657ff675