CIS Ubuntu Linux 16.04 LTS Benchmark v2.0.0 - Control 5.3.9
Description
The IgnoreRhosts parameter specifies that .rhosts and .shosts files will not be used in RhostsRSAAuthentication or HostbasedAuthentication.
Rationale
Setting this parameter forces users to enter a password when authenticating with ssh.
Audit Procedure
Command Line
Run the following command and verify that output matches:
sshd -T -C user=root -C host="$(hostname)" -C addr="$(grep $(hostname) /etc/hosts | awk '{print $1}')" | grep ignorerhosts
Expected Result
ignorerhosts yes
Run the following command and verify the output:
grep -Ei '^\s*ignorerhosts\s+no\b' /etc/ssh/sshd_config
Nothing should be returned.
Remediation
Command Line
Edit the /etc/ssh/sshd_config file to set the parameter as follows:
IgnoreRhosts yes
Default Value
IgnoreRhosts yes
References
- SSHD_CONFIG(5)
CIS Controls
Version 7
9.2 Ensure Only Approved Ports, Protocols and Services Are Running - Ensure that only network ports, protocols, and services listening on a system with validated business needs, are running on each system.
Profile Applicability
- Level 1 - Server
- Level 1 - Workstation
Assessment Status
Automated