Skip to content

The OL 8 SSH daemon must perform strict mode checking of home directory configuration files.

An XCCDF Rule

Description

If other users have access to modify user-specific SSH configuration files, they may be able to log on to the system as another user.

ID
SV-248603r991589_rule
Version
OL08-00-010500
Severity
Medium
References
Updated

Remediation Templates

A Manual Procedure

Configure SSH to perform strict mode checking of home directory configuration files.  
 
Uncomment the "StrictModes" keyword in "/etc/ssh/sshd_config" and set the value to "yes": 
 
StrictModes yes