SLEM-05-232045 - SLEM 5 SSH daemon private host key files must have mode 640 or less permissive.

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

If an unauthorized user obtains the private SSH host key file, the host could be impersonated.

Solution

Configure the mode of SLEM 5 SSH daemon private host key files under "/etc/ssh" to "640" with the following command:

> sudo chmod 640 /etc/ssh/ssh_host*key

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_SLEM_5_V1R2_STIG.zip

Item Details

References: CAT|II, CCI|CCI-000366, Rule-ID|SV-261294r996359_rule, STIG-ID|SLEM-05-232045, Vuln-ID|V-261294

Plugin: Unix

Control ID: e987e22fd798220a5d4ec5f33aa299e0a403da984e3cecc6a8228a2d2639e009