Information
Kerberos authentication for SSH is often implemented using Generic Security Service Application Program Interface (GSSAPI). If Kerberos is enabled through SSH, the SSH daemon provides a means of access to the system's Kerberos implementation. Vulnerabilities in the system's Kerberos implementation may then be subject to exploitation. To reduce the attack surface of the system, the Kerberos authentication mechanism within SSH must be disabled for systems not using this capability.
Solution
Uncomment the 'KerberosAuthentication' keyword in '/etc/ssh/sshd_config' (this file may be named differently or be in a different location if using a version of SSH that is provided by a third-party vendor) and set the value to 'no':
KerberosAuthentication no
The SSH service must be restarted for changes to take effect.
If Kerberos authentication is required, it must be documented, to include the location of the configuration file, with the ISSO.
Item Details
Category: CONFIGURATION MANAGEMENT
References: 800-53|CM-3f., 800-53|CM-5(1), 800-53|CM-6c., 800-53|CM-11(2), CAT|II, CCI|CCI-000318, CCI|CCI-000368, CCI|CCI-001812, CCI|CCI-001813, CCI|CCI-001814, Rule-ID|SV-204599r958796_rule, STIG-ID|RHEL-07-040440, STIG-Legacy|SV-86885, STIG-Legacy|V-72261, Vuln-ID|V-204599
Control ID: ee26d29288ecc6932e5ec4e9c5e94549cff7b0625a53e6a3b581317f8e26a018