OL09-00-002357 - OL 9 must not allow a noncertificate trusted host SSH logon to the system.

Information

SSH trust relationships mean a compromise on one host can allow an attacker to move trivially to other hosts.

Solution

Configure OL 9 to not allow a noncertificate trusted host SSH logon to access the system.

Add or modify the following line in "/etc/ssh/sshd_config" or in a file in "/etc/ssh/sshd_config.d".

HostbasedAuthentication no

Restart the SSH daemon for the settings to take effect:

$ sudo systemctl restart sshd.service

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Oracle_Linux_9_V1R2_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|II, CCI|CCI-000366, Rule-ID|SV-271719r1091869_rule, STIG-ID|OL09-00-002357, Vuln-ID|V-271719

Plugin: Unix

Control ID: dd1d558a95ca30adac1d9d93e965ca173a4b71cf45b4878245ea138b66bae1d6