SV-204592r603261_rule
V-204592
SRG-OS-000480-GPOS-00227
RHEL-07-040370
CAT II
10
Configure SSH to stop users from logging on remotely as the root user.
Edit the appropriate "/etc/ssh/sshd_config" file to uncomment or add the line for the "PermitRootLogin" keyword and set its value to "no" (this file may be named differently or be in a different location if using a version of SSH that is provided by a third-party vendor):
PermitRootLogin no
The SSH service must be restarted for changes to take effect.
Verify remote access using SSH prevents users from logging on directly as root.
Check that SSH prevents users from logging on directly as root with the following command:
# grep -i permitrootlogin /etc/ssh/sshd_config
PermitRootLogin no
If the "PermitRootLogin" keyword is set to "yes", is missing, or is commented out, this is a finding.
V-204592
False
RHEL-07-040370
Verify remote access using SSH prevents users from logging on directly as root.
Check that SSH prevents users from logging on directly as root with the following command:
# grep -i permitrootlogin /etc/ssh/sshd_config
PermitRootLogin no
If the "PermitRootLogin" keyword is set to "yes", is missing, or is commented out, this is a finding.
M
2899