SV-215293r508663_rule
V-215293
SRG-OS-000384-GPOS-00167
AIX7-00-002110
CAT II
10
Obtain the file that contains all the public keys that need to be revoked from ISSO/SA and save the file in /etc/ssh/ directory.
Edit the "/etc/ssh/sshd_config" file to allow "RevokedKeys" to point to the revoked key file obtained above.
Restart the SSH daemon:
# stopsrc -s sshd
# startsrc -s sshd
If public keys are not used for SSH authentication, this is Not Applicable.
Run the following command:
# grep "^RevokedKeys" /etc/ssh/sshd_config
RevokedKeys /etc/ssh/RevokedKeys.txt
If the command does not find the "RevokedKeys" setting, or the value for "RevokedKeys" is set to "none", this is a finding.
V-215293
False
AIX7-00-002110
If public keys are not used for SSH authentication, this is Not Applicable.
Run the following command:
# grep "^RevokedKeys" /etc/ssh/sshd_config
RevokedKeys /etc/ssh/RevokedKeys.txt
If the command does not find the "RevokedKeys" setting, or the value for "RevokedKeys" is set to "none", this is a finding.
M
4012