ALMA-09-021250 - AlmaLinux OS 9 SSH daemon must display the date and time of the last successful account logon upon an SSH logon.

Information

Providing users feedback on when account accesses last occurred facilitates user recognition and reporting of unauthorized account use.

Solution

Configure the SSH daemon to provide users with feedback on when account accesses last occurred.

Add the following line to "/etc/ssh/sshd_config", or uncomment the line and set the value to "yes":

PrintLastLog yes

Alternatively, add the setting to an include file if the line "Include /etc/ssh/sshd_config.d/*.conf" is found at the top of the "/etc/ssh/sshd_config" file:

$ echo 'PrintLastLog yes' > /etc/ssh/sshd_config.d/40-lastlog.conf

Restart the SSH daemon for the settings to take effect:

$ systemctl restart sshd.service

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_CL_AlmaLinux_OS_9_V1R2_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|II, CCI|CCI-000366, Rule-ID|SV-269268r1050150_rule, STIG-ID|ALMA-09-021250, Vuln-ID|V-269268

Plugin: Unix

Control ID: 473308ef8ac6d4dd9940f07d239fa063b0c56545fb9344a242009bbc83b73cd0