SV-230296r627750_rule
V-230296
SRG-OS-000109-GPOS-00056
RHEL-08-010550
CAT II
10
Configure RHEL 8 to stop users from logging on remotely as the "root" user via SSH.
Edit the appropriate "/etc/ssh/sshd_config" file to uncomment or add the line for the "PermitRootLogin" keyword and set its value to "no":
PermitRootLogin no
The SSH daemon must be restarted for the changes to take effect. To restart the SSH daemon, run the following command:
$ sudo systemctl restart sshd.service
Verify remote access using SSH prevents users from logging on directly as "root".
Check that SSH prevents users from logging on directly as "root" with the following command:
$ sudo grep -i PermitRootLogin /etc/ssh/sshd_config
PermitRootLogin no
If the "PermitRootLogin" keyword is set to "yes", is missing, or is commented out, this is a finding.
V-230296
False
RHEL-08-010550
Verify remote access using SSH prevents users from logging on directly as "root".
Check that SSH prevents users from logging on directly as "root" with the following command:
$ sudo grep -i PermitRootLogin /etc/ssh/sshd_config
PermitRootLogin no
If the "PermitRootLogin" keyword is set to "yes", is missing, or is commented out, this is a finding.
M
2921