SV-269270r1050152_rule
V-269270
SRG-OS-000480-GPOS-00227
ALMA-09-021470
CAT II
10
Configure the SSH daemon to not allow X11 forwarding.
Add the following line to "/etc/ssh/sshd_config", or uncomment the line and set the value to "no":
X11forwarding no
Alternatively, add the setting to an include file if the line "Include /etc/ssh/sshd_config.d/*.conf" is found at the top of the "/etc/ssh/sshd_config" file:
$ echo 'X11forwarding no' > /etc/ssh/sshd_config.d/40-x11forwarding.conf
Restart the SSH daemon for the settings to take effect:
$ systemctl restart sshd.service
Verify the SSH daemon does not allow X11Forwarding with the following command:
$ sshd -T | grep x11forwarding
x11forwarding no
If the value is returned as "yes" and X11 forwarding is not documented with the information system security officer (ISSO) as an operational requirement, this is a finding.
V-269270
False
ALMA-09-021470
Verify the SSH daemon does not allow X11Forwarding with the following command:
$ sshd -T | grep x11forwarding
x11forwarding no
If the value is returned as "yes" and X11 forwarding is not documented with the information system security officer (ISSO) as an operational requirement, this is a finding.
M
5664