ALMA-09-021030 - AlmaLinux OS 9 SSH public host key files must have mode 0644 or less permissive.

Information

If a public host key file is modified by an unauthorized user, the SSH service may be compromised.

Whilst public keys are publicly readable, they should not be writeable by nonowners.

Solution

Change the mode of public host key files under "/etc/ssh" to "0644" with the following command:

$ chmod 0644 /etc/ssh/*key.pub

Restart the SSH daemon for the changes to take effect:

$ systemctl restart sshd.service

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_CL_AlmaLinux_OS_9_V1R2_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|II, CCI|CCI-000366, Rule-ID|SV-269266r1050148_rule, STIG-ID|ALMA-09-021030, Vuln-ID|V-269266

Plugin: Unix

Control ID: 4ab330e35ade8dab45df200d34e7376e99a7d396e5f185f55bb885f02dcf4a61