STIGQter STIGQter: STIG Summary: Microsoft Windows Server 2025 Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 01 Jul 2026:

Windows Server 2025 OpenSSH must accept public key authentication.

DISA Rule

SV-285315r1211173_rule

Vulnerability Number

V-285315

Group Title

SRG-OS-000105-GPOS-00052

Rule Version

WN25-SH-000030

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

To configure the system, add or modify the following line in the "$env:ProgramData/ssh/sshd_config" file:

PubkeyAuthentication yes

Restart the OpenSSH service for the settings to take effect.

Check Contents

If OpenSSH is not installed on the system, this requirement is not applicable.
.
If the system administrator demonstrates the use of an approved alternate multifactor authentication method, this requirement is not applicable.

Verify the system accepts public key encryption with the following command:

C:\ > Get-Content "$env:ProgramData\ssh\sshd_config" | Select-String -Pattern '^\s*PubkeyAuthentication'

PubkeyAuthentication yes

If "PubkeyAuthentication" is set to "no", the line is commented out, or the line is missing, this is a finding.

Vulnerability Number

V-285315

Documentable

False

Rule Version

WN25-SH-000030

Severity Override Guidance

If OpenSSH is not installed on the system, this requirement is not applicable.
.
If the system administrator demonstrates the use of an approved alternate multifactor authentication method, this requirement is not applicable.

Verify the system accepts public key encryption with the following command:

C:\ > Get-Content "$env:ProgramData\ssh\sshd_config" | Select-String -Pattern '^\s*PubkeyAuthentication'

PubkeyAuthentication yes

If "PubkeyAuthentication" is set to "no", the line is commented out, or the line is missing, this is a finding.

Check Content Reference

M

Target Key

5719