Cis Ubuntu1804 V220 4 2 18

Ensure sshd PermitEmptyPasswords is disabled

cyberstrikeus Updated

File contents

CIS Ubuntu Linux 18.04 LTS Benchmark v2.2.0 - Control 4.2.18

Profile Applicability

  • Level 1 - Server
  • Level 1 - Workstation

Description

The PermitEmptyPasswords parameter specifies if the SSH server allows login to accounts with empty password strings.

Rationale

Disallowing remote shell access to accounts that have an empty password reduces the probability of unauthorized access to the system.

Audit Procedure

Command Line

Run the following command and verify the output:

sshd -T | grep -i permitemptypasswords

Expected Result

permitemptypasswords no

Remediation

Command Line

Edit the /etc/ssh/sshd_config file to set the parameter as follows:

PermitEmptyPasswords no

Default Value

PermitEmptyPasswords no

References

  1. NIST SP 800-53 Rev. 5: CM-7

CIS Controls

v8 - 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software.

v7 - 9.2 Ensure Only Approved Ports, Protocols, and Services Are Running.

Profile Applicability

  • Level 1 - Server
  • Level 1 - Workstation

Assessment Status

Automated

cyberstrikeus/cyberstrike/tree/main/.cyberstrike/skill/CIS_benchmarks/Operating_Systems/Ubuntu/cis-ubuntu-linux-18-04-lts-benchmark-v2/cis-ubuntu1804-v220-4-2-18 commit d48e56a60a

Frequently asked questions

npx skillmds@latest add cyberstrikeus/cis-ubuntu1804-v220-4-2-18