Cis Ubuntu1204 V110 9 3 6

Set SSH IgnoreRhosts to Yes

cyberstrikeus Updated

File contents

9.3.6 Set SSH IgnoreRhosts to Yes (Scored)

Profile Applicability

  • Level 1

Description

The IgnoreRhosts parameter specifies that .rhosts and .shosts files will not be used in RhostsRSAAuthentication or HostbasedAuthentication.

Rationale

Setting this parameter forces users to enter a password when authenticating with ssh.

Audit Procedure

Using Command Line

To verify the correct SSH setting, run the following command and verify that the output is as shown:

grep "^IgnoreRhosts" /etc/ssh/sshd_config

Expected Result

IgnoreRhosts yes

Remediation

Using Command Line

Edit the /etc/ssh/sshd_config file to set the parameter as follows:

IgnoreRhosts yes

Default Value

IgnoreRhosts yes

References

  • CIS Ubuntu 12.04 LTS Server Benchmark v1.1.0

Profile

Level 1 - Scored

cyberstrikeus/cyberstrike/tree/main/.cyberstrike/skill/CIS_benchmarks/Operating_Systems/Ubuntu/cis-ubuntu-12-04-lts-server-benchmark/cis-ubuntu1204-v110-9-3-6 commit 8332354849

Frequently asked questions

npx skillmds@latest add cyberstrikeus/cis-ubuntu1204-v110-9-3-6