SV-217273r603961_rule
V-217273
SRG-OS-000163-GPOS-00072
SLES-12-030191
CAT II
10
Configure the SUSE operating system to automatically terminate all network connections associated with SSH traffic at the end of a session or after a "10" minute period of inactivity.
Modify or append the following lines in the "/etc/ssh/sshd_config" file:
ClientAliveCountMax 1
In order for the changes to take effect, the SSH daemon must be restarted.
# sudo systemctl restart sshd.service
Verify that all network connections associated with SSH traffic are automatically terminated at the end of the session or after "10" minutes of inactivity.
Check that the "ClientAliveCountMax" variable is set to a value of "1" or less by performing the following command:
# sudo grep -i clientalive /etc/ssh/sshd_config
ClientAliveInterval 600
ClientAliveCountMax 1
If "ClientAliveCountMax" does not exist or "ClientAliveCountMax" is not set to a value of "1" in "/etc/ssh/sshd_config", or the line is commented out, this is a finding.
V-217273
False
SLES-12-030191
Verify that all network connections associated with SSH traffic are automatically terminated at the end of the session or after "10" minutes of inactivity.
Check that the "ClientAliveCountMax" variable is set to a value of "1" or less by performing the following command:
# sudo grep -i clientalive /etc/ssh/sshd_config
ClientAliveInterval 600
ClientAliveCountMax 1
If "ClientAliveCountMax" does not exist or "ClientAliveCountMax" is not set to a value of "1" in "/etc/ssh/sshd_config", or the line is commented out, this is a finding.
M
4033