Cis GCP Cos 5.1.11

Ensure SSH PermitEmptyPasswords is disabled

cyberstrikeus Updated

File contents

5.1.11 Ensure SSH PermitEmptyPasswords is disabled (Automated)

Description

The PermitEmptyPasswords parameter specifies if the SSH server allows login to accounts with empty password strings.

Rationale

Disallowing remote shell access to accounts that have an empty password reduces the probability of unauthorized access to the system.

Audit Procedure

Run the following command and verify that output matches:

# sshd -T | grep permitemptypasswords

PermitEmptyPasswords no

Expected Result

Output should show PermitEmptyPasswords no.

Remediation

Edit the /etc/ssh/sshd_config file to set the parameter as follows:

PermitEmptyPasswords no

Default Value

PermitEmptyPasswords no

CIS Controls

Controls Version Control IG 1 IG 2 IG 3
v8 6.3 Require MFA for Externally-Exposed Applications x x
v7 16.3 Require Multi-factor Authentication x x

Profile

  • Level 1 - Server

cyberstrikeus/cyberstrike/tree/main/.cyberstrike/skill/CIS_benchmarks/Cloud_Providers/Google_Cloud_Platform/cis-google-container-optimized-os/cis-gcp-cos-5.1.11 commit d931c5c80e

Frequently asked questions

npx skillmds@latest add cyberstrikeus/cis-gcp-cos-5-1-11