STIGQter STIGQter: STIG Summary: Cloud Linux AlmaLinux OS 9 Security Technical Implementation Guide Version: 1 Release: 7 Benchmark Date: 01 Jul 2026:

The SSH daemon must perform strict mode checking of home directory configuration files.

DISA Rule

SV-269299r1050181_rule

Vulnerability Number

V-269299

Group Title

SRG-OS-000480-GPOS-00230

Rule Version

ALMA-09-024770

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

To configure the SSH daemon to perform strict mode checking of home directory configuration files, add or modify the following line in "/etc/ssh/sshd_config", or uncomment the line and set the value to "yes":

StrictModes yes

Alternatively, add the setting to an include file if the line "Include /etc/ssh/sshd_config.d/*.conf" is found at the top of the "/etc/ssh/sshd_config" file:

$ echo "StrictModes yes" > /etc/ssh/sshd_config.d/strictmodes.conf

Restart the SSH daemon for the settings to take effect:

$ systemctl restart sshd.service

Check Contents

Verify the SSH daemon performs strict mode checking of home directory configuration files with the following command:

$ sshd -T | grep strictmodes

strictmodes yes

If the "StrictModes" keyword is set to "no", or no output is returned, this is a finding.

Vulnerability Number

V-269299

Documentable

False

Rule Version

ALMA-09-024770

Severity Override Guidance

Verify the SSH daemon performs strict mode checking of home directory configuration files with the following command:

$ sshd -T | grep strictmodes

strictmodes yes

If the "StrictModes" keyword is set to "no", or no output is returned, this is a finding.

Check Content Reference

M

Target Key

5664