ESXI-06-000014 - The SSH daemon must not permit root logins.

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Permitting direct root login reduces auditable information about who ran privileged commands on the system and also allows direct attack attempts on root's password.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

The root user should never be allowed to log in to a system directly over a network.

Add or correct the following line in '/etc/ssh/sshd_config':

PermitRootLogin no

See Also

http://iasecontent.disa.mil/stigs/zip/U_VMware_vSphere_6-0_ESXi_V1R4_STIG.zip

Item Details

References: CAT|III, CCI|CCI-000366, Group-ID|V-63197, Rule-ID|SV-77687r1_rule, STIG-ID|ESXI-06-000014

Plugin: VMware

Control ID: 6fa1b60ec10b965ca2475cd698ca84ba7fe067ddef1f456b7e76642cdbcd8d1f