SOL-11.1-040360 - Direct root account login must not be permitted for SSH access.

Information

The system should not allow users to log in as the root user directly, as audited actions would be non-attributable to a specific user.

Solution

The root role is required.

Modify the sshd_config file

# pfedit /etc/ssh/sshd_config

Locate the line containing:

PermitRootLogin

Change it to:

PermitRootLogin no

Restart the SSH service.

# svcadm restart svc:/network/ssh

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_SOL_11_SPARC_V3R6_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|II, CCI|CCI-000366, Rule-ID|SV-216354r959010_rule, STIG-ID|SOL-11.1-040360, STIG-Legacy|SV-60975, STIG-Legacy|V-48103, Vuln-ID|V-216354

Plugin: Unix

Control ID: 54241b14cae04bc32a47ec87c06b3883da139c92ec096d4041baeb05e46d2609