STIGQter STIGQter: STIG Summary: VMware ESX 3 Server Version: 1 Release: 2 Benchmark Date: 22 Jul 2016: The SSH daemon must not permit Kerberos authentication unless needed.

DISA Rule

SV-26768r1_rule

Vulnerability Number

V-22475

Group Title

GEN005526

Rule Version

GEN005526

Severity

CAT III

CCI(s)

Weight

10

Fix Recommendation

Edit the SSH daemon configuration and set (add if necessary) a KerberosAuthentication directive set to no.

Check Contents

Ask the SA if Kerberos authentication is used by the system. If it is, this is not applicable.

Check the SSH daemon configuration for the Kerberos authentication setting.
# grep -i KerberosAuthentication /etc/ssh/sshd_config | grep -v '^#'
If no lines are returned, or the setting is set to yes, this is a finding.

Vulnerability Number

V-22475

Documentable

False

Rule Version

GEN005526

Severity Override Guidance

Ask the SA if Kerberos authentication is used by the system. If it is, this is not applicable.

Check the SSH daemon configuration for the Kerberos authentication setting.
# grep -i KerberosAuthentication /etc/ssh/sshd_config | grep -v '^#'
If no lines are returned, or the setting is set to yes, this is a finding.

Check Content Reference

M

Responsibility

System Administrator

Target Key

1386

Comments