SV-274066r1120186_rule
V-274066
SRG-OS-000228-GPOS-00088
AZLX-23-002005
CAT II
10
Configure Amazon Linux 2023 to display the Standard Mandatory DOD Notice and Consent Banner before granting access to the system via ssh.
Edit the "etc/ssh/sshd_config" file or a file in "/etc/ssh/sshd_config.d" to uncomment the banner keyword and configure it to point to a file that will contain the logon banner (this file may be named differently or be in a different location if using a version of SSH that is provided by a third-party vendor).
An example configuration line is:
Banner /etc/issue
Verify Amazon Linux 2023 displays the Standard Mandatory DOD Notice and Consent Banner before granting access to the system from any SSH connection.
Check for the location of the banner file being used with the following command:
$ sudo /usr/sbin/sshd -dd 2>&1 | awk '/filename/ {print $4}' | tr -d '\r' | tr '\n' ' ' | xargs sudo grep -iH '^\s*banner'
/etc/ssh/sshd_config.d/80-bannerPointer.conf:Banner /etc/issue
This command will return the banner keyword and the name of the file that contains the SSH banner (in this case "/etc/issue").
If the line is commented out, this is a finding.
V-274066
False
AZLX-23-002005
Verify Amazon Linux 2023 displays the Standard Mandatory DOD Notice and Consent Banner before granting access to the system from any SSH connection.
Check for the location of the banner file being used with the following command:
$ sudo /usr/sbin/sshd -dd 2>&1 | awk '/filename/ {print $4}' | tr -d '\r' | tr '\n' ' ' | xargs sudo grep -iH '^\s*banner'
/etc/ssh/sshd_config.d/80-bannerPointer.conf:Banner /etc/issue
This command will return the banner keyword and the name of the file that contains the SSH banner (in this case "/etc/issue").
If the line is commented out, this is a finding.
M
5700