SV-258007r1045073_rule
V-258007
SRG-OS-000480-GPOS-00227
RHEL-09-255155
CAT II
10
Configure the SSH daemon to not allow X11 forwarding.
Add the following line to "/etc/ssh/sshd_config" or to a file in "/etc/ssh/sshd_config.d", or uncomment the line and set the value to "no":
X11forwarding no
The SSH service must be restarted for changes to take effect:
$ sudo systemctl restart sshd.service
Verify the SSH daemon does not allow X11Forwarding with the following command:
$ sudo /usr/sbin/sshd -dd 2>&1 | awk '/filename/ {print $4}' | tr -d '\r' | tr '\n' ' ' | xargs sudo grep -iH '^\s*x11forwarding'
X11forwarding no
If the value is returned as "yes", the returned line is commented out, or no output is returned, and X11 forwarding is not documented with the information system security officer (ISSO) as an operational requirement, this is a finding.
V-258007
False
RHEL-09-255155
Verify the SSH daemon does not allow X11Forwarding with the following command:
$ sudo /usr/sbin/sshd -dd 2>&1 | awk '/filename/ {print $4}' | tr -d '\r' | tr '\n' ' ' | xargs sudo grep -iH '^\s*x11forwarding'
X11forwarding no
If the value is returned as "yes", the returned line is commented out, or no output is returned, and X11 forwarding is not documented with the information system security officer (ISSO) as an operational requirement, this is a finding.
M
5551