STIGQter STIGQter: STIG Summary: Solaris 10 SPARC Security Technical Implementation Guide Version: 2 Release: 2 Benchmark Date: 22 Jan 2021:

The SSH daemon must not permit GSSAPI authentication unless needed.

DISA Rule

SV-226995r603265_rule

Vulnerability Number

V-226995

Group Title

SRG-OS-000480

Rule Version

GEN005524

Severity

CAT III

CCI(s)

Weight

10

Fix Recommendation

Edit the SSH daemon configuration and set (add if necessary) a GSSAPIAuthentication directive set to no.

Check Contents

Ask the SA if GSSAPI authentication is used for SSH authentication to the system. If so, this is not applicable.

Check the SSH daemon configuration for the GSSAPI authentication setting.
# grep -i GSSAPIAuthentication /etc/ssh/sshd_config | grep -v '^#'
If no lines are returned, or the setting is set to yes, this is a finding.

Vulnerability Number

V-226995

Documentable

False

Rule Version

GEN005524

Severity Override Guidance

Ask the SA if GSSAPI authentication is used for SSH authentication to the system. If so, this is not applicable.

Check the SSH daemon configuration for the GSSAPI authentication setting.
# grep -i GSSAPIAuthentication /etc/ssh/sshd_config | grep -v '^#'
If no lines are returned, or the setting is set to yes, this is a finding.

Check Content Reference

M

Target Key

4060

Comments