SLES-15-040240 - The SUSE operating system SSH daemon public host key files must have mode 0644 or less permissive.

Information

If a public host key file is modified by an unauthorized user, the SSH service may be compromised.

Solution

Configure the SUSE operating system SSH daemon public host key files have mode "0644" or less permissive.

Note: SSH public key files may be found in other directories on the system depending on the installation.

Change the mode of public host key files under "/etc/ssh" to "0644" with the following command:

> sudo chmod 0644 /etc/ssh/ssh_host*key.pub

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_SLES_15_V2R4_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|II, CCI|CCI-000366, Rule-ID|SV-235008r991589_rule, STIG-ID|SLES-15-040240, Vuln-ID|V-235008

Plugin: Unix

Control ID: 5610e8968412b661979e957f446f4c8066a04fc3bfc70e90b52aa2f14513a3c5