SV-204598r603261_rule
V-204598
SRG-OS-000364-GPOS-00151
RHEL-07-040430
CAT II
10
Uncomment the "GSSAPIAuthentication" keyword in "/etc/ssh/sshd_config" (this file may be named differently or be in a different location if using a version of SSH that is provided by a third-party vendor) and set the value to "no":
GSSAPIAuthentication no
The SSH service must be restarted for changes to take effect.
If GSSAPI authentication is required, it must be documented, to include the location of the configuration file, with the ISSO.
Verify the SSH daemon does not permit GSSAPI authentication unless approved.
Check that the SSH daemon does not permit GSSAPI authentication with the following command:
# grep -i gssapiauth /etc/ssh/sshd_config
GSSAPIAuthentication no
If the "GSSAPIAuthentication" keyword is missing, is set to "yes" and is not documented with the Information System Security Officer (ISSO), or the returned line is commented out, this is a finding.
V-204598
False
RHEL-07-040430
Verify the SSH daemon does not permit GSSAPI authentication unless approved.
Check that the SSH daemon does not permit GSSAPI authentication with the following command:
# grep -i gssapiauth /etc/ssh/sshd_config
GSSAPIAuthentication no
If the "GSSAPIAuthentication" keyword is missing, is set to "yes" and is not documented with the Information System Security Officer (ISSO), or the returned line is commented out, this is a finding.
M
2899