CIS Ubuntu 14.04 LTS - 5.2.9 Ensure SSH PermitEmptyPasswords is disabled

Verify SSH PermitEmptyPasswords is set to no to prevent login with empty passwords

cyberstrikeus Updated

File contents

5.2.9 Ensure SSH PermitEmptyPasswords is disabled (Scored)

Profile Applicability

  • Level 1 - Server
  • Level 1 - Workstation

Description

The PermitEmptyPasswords parameter specifies if the SSH server allows login to accounts with empty password strings.

Rationale

Disallowing remote shell access to accounts that have an empty password reduces the probability of unauthorized access to the system.

Audit Procedure

Run the following command and verify that output matches:

grep "^PermitEmptyPasswords" /etc/ssh/sshd_config

Expected Result

PermitEmptyPasswords no

Remediation

Edit the /etc/ssh/sshd_config file to set the parameter as follows:

PermitEmptyPasswords no

Default Value

PermitEmptyPasswords no

References

  • CIS Controls: 16 - Account Monitoring and Control

Profile

  • Level 1 - Server
  • Level 1 - Workstation

cyberstrikeus/cyberstrike/tree/main/.cyberstrike/skill/CIS_benchmarks/Operating_Systems/Ubuntu/cis-ubuntu-linux-14-04-lts-benchmark-v2/cis-ubuntu1404-v210-5-2-9 commit 8a142b538e

Frequently asked questions

npx skillmds@latest add cyberstrikeus/cis-ubuntu-14-04-lts-5-2-9-ensure-ssh-permitemptypasswords-i