SV-209056r603263_rule
V-209056
SRG-OS-000025
OL6-00-000507
CAT II
10
Update the "PrintLastLog" keyword to "yes" in /etc/ssh/sshd_config:
PrintLastLog yes
While it is acceptable to remove the keyword entirely since the default action for the SSH daemon is to print the last login date and time, it is preferred to have the value explicitly documented.
Verify the value associated with the "PrintLastLog" keyword in /etc/ssh/sshd_config:
# grep -i "^PrintLastLog" /etc/ssh/sshd_config
If the "PrintLastLog" keyword is not present, this is not a finding. If the value is not set to "yes", this is a finding.
V-209056
False
OL6-00-000507
Verify the value associated with the "PrintLastLog" keyword in /etc/ssh/sshd_config:
# grep -i "^PrintLastLog" /etc/ssh/sshd_config
If the "PrintLastLog" keyword is not present, this is not a finding. If the value is not set to "yes", this is a finding.
M
2928