SV-225135r610901_rule
V-225135
SRG-OS-000023-GPOS-00006
AOSX-15-000024
CAT II
10
For systems that allow remote access through SSH, run the following command:
# /usr/bin/sudo /usr/bin/sed -i.bak 's/^#Banner.*/Banner \/etc\/banner/' /etc/ssh/sshd_config
For systems that allow remote access through SSH, run the following command to verify that "/etc/banner" is displayed before granting access:
# /usr/bin/grep Banner /etc/ssh/sshd_config
Banner /etc/banner
If the sshd Banner configuration option does not point to "/etc/banner", this is a finding.
V-225135
False
AOSX-15-000024
For systems that allow remote access through SSH, run the following command to verify that "/etc/banner" is displayed before granting access:
# /usr/bin/grep Banner /etc/ssh/sshd_config
Banner /etc/banner
If the sshd Banner configuration option does not point to "/etc/banner", this is a finding.
M
4212