STIGQter STIGQter: STIG Summary: Red Hat Enterprise Linux 10 Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 01 Jul 2026:

RHEL 10 must be configured so that Secure Shell (SSH) public host key files have mode "0644" or less permissive.

DISA Rule

SV-281253r1184654_rule

Vulnerability Number

V-281253

Group Title

SRG-OS-000445-GPOS-00199

Rule Version

RHEL-10-700500

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure RHEL 10 SSH public host key files to have mode "0644" or less permissive.

Change the mode of public host key files under "/etc/ssh" to "0644" with the following command:

$ sudo chmod 0644 /etc/ssh/*key.pub

Restart the SSH daemon with the following command for the changes to take effect:

$ sudo systemctl restart sshd.service

Check Contents

Verify RHEL 10 SSH public host key files have a mode of "0644" or less permissive with the following command:

Note: SSH public key files may be found in other directories on the system depending on the installation.

$ sudo stat -c "%a %n" /etc/ssh/*.pub
644 /etc/ssh/ssh_host_dsa_key.pub
644 /etc/ssh/ssh_host_ecdsa_key.pub
644 /etc/ssh/ssh_host_ed25519_key.pub
644 /etc/ssh/ssh_host_rsa_key.pub

If any "key.pub" file has a mode more permissive than "0644", this is a finding.

Vulnerability Number

V-281253

Documentable

False

Rule Version

RHEL-10-700500

Severity Override Guidance

Verify RHEL 10 SSH public host key files have a mode of "0644" or less permissive with the following command:

Note: SSH public key files may be found in other directories on the system depending on the installation.

$ sudo stat -c "%a %n" /etc/ssh/*.pub
644 /etc/ssh/ssh_host_dsa_key.pub
644 /etc/ssh/ssh_host_ecdsa_key.pub
644 /etc/ssh/ssh_host_ed25519_key.pub
644 /etc/ssh/ssh_host_rsa_key.pub

If any "key.pub" file has a mode more permissive than "0644", this is a finding.

Check Content Reference

M

Target Key

5733