SV-252913r958450_rule
V-252913
SRG-OS-000067-GPOS-00035
TOSS-04-010020
CAT II
10
Create a new private and public key pair that utilizes a passcode with the following command:
$ sudo ssh-keygen -n [passphrase]
Verify the operating system, for PKI-based authentication, enforces authorized access to the corresponding private key.
If the system does not allow PKI authentication, this requirement is Not Applicable.
Verify the SSH private key files have a passphrase.
For each private key stored on the system, use the following command:
$ sudo ssh-keygen -y -f /path/to/file
If the contents of the key are displayed, and use of un-passphrased SSH keys is not documented with the Information System Security Officer (ISSO), this is a finding.
V-252913
False
TOSS-04-010020
Verify the operating system, for PKI-based authentication, enforces authorized access to the corresponding private key.
If the system does not allow PKI authentication, this requirement is Not Applicable.
Verify the SSH private key files have a passphrase.
For each private key stored on the system, use the following command:
$ sudo ssh-keygen -y -f /path/to/file
If the contents of the key are displayed, and use of un-passphrased SSH keys is not documented with the Information System Security Officer (ISSO), this is a finding.
M
5469