PHTN-67-000035 - The Photon operating system must configure sshd to disallow root logins.

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Logging on with a user-specific account provides individual accountability for actions performed on the system. Users must log in with their individual accounts and elevate to root as necessary. Disallowing root SSH login also reduces the distribution of the root password to users who may not otherwise need that level of privilege.

Solution

Open /etc/ssh/sshd_config with a text editor and ensure that the 'PermitRootLogin' line is uncommented and set to the following:

PermitRootLogin no

At the command line, execute the following command:

# service sshd reload

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_VMW_vSphere_6-7_Y22M04_STIG.zip

Item Details

References: CAT|II, CCI|CCI-000770, Rule-ID|SV-239107r675129_rule, STIG-ID|PHTN-67-000035, Vuln-ID|V-239107

Plugin: Unix

Control ID: 8d2580234c2d8ce943dc48eeac70958156453e910ea1384f52236faf15f3ffd0