STIGQter STIGQter: STIG Summary: Microsoft Windows Server 2025 Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 01 Jul 2026:

Windows Server 2025 OpenSSH must not allow GSSAPI authentication.

DISA Rule

SV-285323r1211197_rule

Vulnerability Number

V-285323

Group Title

SRG-OS-000364-GPOS-00151

Rule Version

WN25-SH-000110

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

To configure the system, add or modify the following line in the "$env:ProgramData/ssh/sshd_config" file:

GSSAPIAuthentication no

Restart the OpenSSH service for the settings to take effect.

Check Contents

If OpenSSH is not installed on the system, this requirement is not applicable.

Verify the system does not allow GSSAPI authentication with the following command:

C:\ > Get-Content "$env:ProgramData\ssh\sshd_config" | Select-String -Pattern '^\s*GSSAPIAuthentication'

GSSAPIAuthentication no

If the value is returned as "yes", the returned line is commented out, or no output is returned, this is a finding.

Vulnerability Number

V-285323

Documentable

False

Rule Version

WN25-SH-000110

Severity Override Guidance

If OpenSSH is not installed on the system, this requirement is not applicable.

Verify the system does not allow GSSAPI authentication with the following command:

C:\ > Get-Content "$env:ProgramData\ssh\sshd_config" | Select-String -Pattern '^\s*GSSAPIAuthentication'

GSSAPIAuthentication no

If the value is returned as "yes", the returned line is commented out, or no output is returned, this is a finding.

Check Content Reference

M

Target Key

5719