CIS Ubuntu 14.04 LTS - 5.2.1 Ensure permissions on /etc/ssh/sshd_config are configured

Verify /etc/ssh/sshd_config ownership and permissions are restricted to root with no group/other access

cyberstrikeus Updated

File contents

5.2.1 Ensure permissions on /etc/ssh/sshd_config are configured (Scored)

Profile Applicability

  • Level 1 - Server
  • Level 1 - Workstation

Description

The /etc/ssh/sshd_config file contains configuration specifications for sshd. The command below sets the owner and group of the file to root.

Rationale

The /etc/ssh/sshd_config file needs to be protected from unauthorized changes by non-privileged users.

Audit Procedure

Run the following command and verify Uid and Gid are both 0/root and Access does not grant permissions to group or other:

stat /etc/ssh/sshd_config

Expected Result

Access: (0600/-rw-------)  Uid: (    0/    root)   Gid: (    0/    root)

Remediation

Run the following commands to set ownership and permissions on /etc/ssh/sshd_config:

chown root:root /etc/ssh/sshd_config
chmod og-rwx /etc/ssh/sshd_config

Default Value

Not configured by default.

References

  • CIS Controls: 5.1 - Minimize And Sparingly Use Administrative Privileges

Profile

  • Level 1 - Server
  • Level 1 - Workstation

cyberstrikeus/cyberstrike/tree/main/.cyberstrike/skill/CIS_benchmarks/Operating_Systems/Ubuntu/cis-ubuntu-linux-14-04-lts-benchmark-v2/cis-ubuntu1404-v210-5-2-1 commit 836eb48a42

Frequently asked questions

npx skillmds@latest add cyberstrikeus/cis-ubuntu-14-04-lts-5-2-1-ensure-permissions-on-etc-ssh-ssh