Skip to content

The TOSS SSH daemon must perform strict mode checking of home directory configuration files.

An XCCDF Rule

Description

If other users have access to modify user-specific SSH configuration files, they may be able to log on to the system as another user.

ID
SV-253106r991589_rule
Version
TOSS-04-040650
Severity
Medium
References
Updated

Remediation Templates

A Manual Procedure

Configure SSH to perform strict mode checking of home directory configuration files. Uncomment the "StrictModes" keyword in "/etc/ssh/sshd_config" and set the value to "yes":

StrictModes yes

The SSH daemon must be restarted for the changes to take effect. To restart the SSH daemon, run the following command:

$ sudo systemctl restart sshd.service