GEN002100 - The .rhosts file must not be supported in PAM.

Information

.rhosts files are used to specify a list of hosts permitted remote access to a particular account without authenticating. The use of such a mechanism defeats strong identification and authentication requirements.

Solution

Edit the file(s) in /etc/pam.d referencing the rhosts_auth module, and remove the references to the rhosts_auth module.

See Also

http://iasecontent.disa.mil/stigs/zip/U_RedHat_5_V1R18_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|II, CCI|CCI-000366, Group-ID|V-11989, Rule-ID|SV-37389r1_rule, STIG-ID|GEN002100, Vuln-ID|V-11989

Plugin: Unix

Control ID: f2c54077d28d4e39bbc4ac129dd7cc9fb5ff5b5b0d392dfdc8a8da62a44e34f9