STIGQter STIGQter: STIG Summary: Red Hat Enterprise Linux 10 Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 01 Jul 2026:

RHEL 10 must be configured so that SSHD accepts public key authentication.

DISA Rule

SV-281263r1184763_rule

Vulnerability Number

V-281263

Group Title

SRG-OS-000105-GPOS-00052

Rule Version

RHEL-10-700600

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure RHEL 10 to accept public key authentication.

In "/etc/ssh/sshd_config.d", create a drop file that will lexicographically precede 50-redhat.conf and add the following line:

PubkeyAuthentication yes

Restart the SSH daemon with the following command for the settings to take effect:

$ sudo systemctl restart sshd.service

Check Contents

Note: If the system administrator demonstrates the use of an approved alternate multifactor authentication method, this requirement is not applicable.

Verify RHEL 10 SSH daemons accept public key encryption with the following command:

$ sudo /usr/sbin/sshd -dd 2>&1 | awk '/filename/ {print $4}' | tr -d '\r' | tr '\n' ' ' | xargs sudo grep -iH '^\s*pubkeyauthentication'
/etc/ssh/sshd_config.d/10-stig.conf:PubkeyAuthentication yes

Verify the runtime setting with the following command:

$ sudo sshd -T | grep -i pubkeyauthentication
pubkeyauthentication yes

If the "PubkeyAuthentication" keyword is not set to "yes" in a drop-in that lexicographically precedes 50-redhat.conf, or if no output is returned, this is a finding.

Vulnerability Number

V-281263

Documentable

False

Rule Version

RHEL-10-700600

Severity Override Guidance

Note: If the system administrator demonstrates the use of an approved alternate multifactor authentication method, this requirement is not applicable.

Verify RHEL 10 SSH daemons accept public key encryption with the following command:

$ sudo /usr/sbin/sshd -dd 2>&1 | awk '/filename/ {print $4}' | tr -d '\r' | tr '\n' ' ' | xargs sudo grep -iH '^\s*pubkeyauthentication'
/etc/ssh/sshd_config.d/10-stig.conf:PubkeyAuthentication yes

Verify the runtime setting with the following command:

$ sudo sshd -T | grep -i pubkeyauthentication
pubkeyauthentication yes

If the "PubkeyAuthentication" keyword is not set to "yes" in a drop-in that lexicographically precedes 50-redhat.conf, or if no output is returned, this is a finding.

Check Content Reference

M

Target Key

5733