Cis GCP Cos 5.1.22

Ensure SSH MaxSessions is set to 4 or less

cyberstrikeus Updated

File contents

5.1.22 Ensure SSH MaxSessions is set to 4 or less (Automated)

Description

The MaxSessions parameter specifies the maximum number of open sessions permitted from a given connection.

Rationale

To protect a system from denial of service due to a large number of concurrent sessions, use the rate limiting function of MaxSessions to protect availability of sshd logins and prevent overwhelming the daemon.

Audit Procedure

Run the following command and verify that output MaxSessions is 4 or less, or matches site policy:

# sshd -T | grep -i maxsessions
# maxsessions 4

Expected Result

Output should show maxsessions 4 or less, or match site policy.

Remediation

Edit the /etc/ssh/sshd_config file to set the parameter as follows:

MaxSessions 4

CIS Controls

Controls Version Control IG 1 IG 2 IG 3
v7 5.1 Establish Secure Configurations x x x

Profile

  • Level 2 - Server

cyberstrikeus/cyberstrike/tree/main/.cyberstrike/skill/CIS_benchmarks/Cloud_Providers/Google_Cloud_Platform/cis-google-container-optimized-os/cis-gcp-cos-5.1.22 commit 8a8f82556f

Frequently asked questions

npx skillmds@latest add cyberstrikeus/cis-gcp-cos-5-1-22