SV-239164r675300_rule
V-239164
SRG-OS-000480-GPOS-00227
PHTN-67-000093
CAT II
10
Open /etc/ssh/sshd_config with a text editor.
Ensure that the "IgnoreUserKnownHosts" line is uncommented and set to the following:
IgnoreUserKnownHosts yes
At the command line, execute the following command:
# service sshd reload
At the command line, execute the following command:
# sshd -T|&grep -i IgnoreUserKnownHosts
Expected result:
IgnoreUserKnownHosts yes
If the output does not match the expected result, this is a finding.
V-239164
False
PHTN-67-000093
At the command line, execute the following command:
# sshd -T|&grep -i IgnoreUserKnownHosts
Expected result:
IgnoreUserKnownHosts yes
If the output does not match the expected result, this is a finding.
M
5323