SV-215292r508663_rule
V-215292
SRG-OS-000373-GPOS-00158
AIX7-00-002108
CAT II
10
Edit "/etc/ssh/sshd_config" and remove the "GSSAPIAuthentication" setting or change the value to "no".
Refresh sshd:
# stopsrc -s sshd
# startsrc -s sshd
Ask the SA if GSSAPI authentication is used for SSH authentication to the system. If so, this is not applicable.
Check the SSH daemon configuration for the GSSAPI authentication setting:
# grep -i GSSAPIAuthentication /etc/ssh/sshd_config | grep -v '^#'
GSSAPIAuthentication no
If the setting is not set to "no", this is a finding.
V-215292
False
AIX7-00-002108
Ask the SA if GSSAPI authentication is used for SSH authentication to the system. If so, this is not applicable.
Check the SSH daemon configuration for the GSSAPI authentication setting:
# grep -i GSSAPIAuthentication /etc/ssh/sshd_config | grep -v '^#'
GSSAPIAuthentication no
If the setting is not set to "no", this is a finding.
M
4012