SV-239186r675366_rule
V-239186
SRG-OS-000480-GPOS-00227
PHTN-67-000115
CAT II
10
At the command line, execute the following commands for each returned file:
# chmod 644 <file>
# chown root:root <file>
At the command line, execute the following command:
# stat -c "%n permissions are %a and owned by %U:%G" /etc/ssh/*key.pub
Expected result:
/etc/ssh/ssh_host_dsa_key.pub permissions are 644 and owned by root:root
/etc/ssh/ssh_host_ecdsa_key.pub permissions are 644 and owned by root:root
/etc/ssh/ssh_host_ed25519_key.pub permissions are 644 and owned by root:root
/etc/ssh/ssh_host_rsa_key.pub permissions are 644 and owned by root:root
If the output does not match the expected result, this is a finding.
V-239186
False
PHTN-67-000115
At the command line, execute the following command:
# stat -c "%n permissions are %a and owned by %U:%G" /etc/ssh/*key.pub
Expected result:
/etc/ssh/ssh_host_dsa_key.pub permissions are 644 and owned by root:root
/etc/ssh/ssh_host_ecdsa_key.pub permissions are 644 and owned by root:root
/etc/ssh/ssh_host_ed25519_key.pub permissions are 644 and owned by root:root
/etc/ssh/ssh_host_rsa_key.pub permissions are 644 and owned by root:root
If the output does not match the expected result, this is a finding.
M
5323