STIGQter STIGQter: STIG Summary: VMware ESX 3 Server Version: 1 Release: 2 Benchmark Date: 22 Jul 2016: The SSH daemon must not permit GSSAPI authentication unless needed.

DISA Rule

SV-26766r1_rule

Vulnerability Number

V-22473

Group Title

GEN005524

Rule Version

GEN005524

Severity

CAT III

CCI(s)

Weight

10

Fix Recommendation

Edit the SSH daemon configuration and set (add if necessary) a GSSAPIAuthentication directive set to no.

Check Contents

Ask the SA if GSSAPI authentication is used for SSH authentication to the system. If so, this is not applicable.

Check the SSH daemon configuration for the GSSAPI authentication setting.
# grep -i GSSAPIAuthentication /etc/ssh/sshd_config | grep -v '^#'
If no lines are returned, or the setting is set to yes, this is a finding.

Vulnerability Number

V-22473

Documentable

False

Rule Version

GEN005524

Severity Override Guidance

Ask the SA if GSSAPI authentication is used for SSH authentication to the system. If so, this is not applicable.

Check the SSH daemon configuration for the GSSAPI authentication setting.
# grep -i GSSAPIAuthentication /etc/ssh/sshd_config | grep -v '^#'
If no lines are returned, or the setting is set to yes, this is a finding.

Check Content Reference

M

Responsibility

System Administrator

Target Key

1386

Comments