SV-239187r675369_rule
V-239187
SRG-OS-000480-GPOS-00227
PHTN-67-000116
CAT II
10
At the command line, execute the following commands for each returned file:
# chmod 600 <file>
# chown root:root <file>
At the command line, execute the following command:
# stat -c "%n permissions are %a and owned by %U:%G" /etc/ssh/*key
Expected result:
/etc/ssh/ssh_host_dsa_key permissions are 600 and owned by root:root
/etc/ssh/ssh_host_ecdsa_key permissions are 600 and owned by root:root
/etc/ssh/ssh_host_ed25519_key permissions are 600 and owned by root:root
/etc/ssh/ssh_host_rsa_key permissions are 600 and owned by root:root
If the output does not match the expected result, this is a finding.
V-239187
False
PHTN-67-000116
At the command line, execute the following command:
# stat -c "%n permissions are %a and owned by %U:%G" /etc/ssh/*key
Expected result:
/etc/ssh/ssh_host_dsa_key permissions are 600 and owned by root:root
/etc/ssh/ssh_host_ecdsa_key permissions are 600 and owned by root:root
/etc/ssh/ssh_host_ed25519_key permissions are 600 and owned by root:root
/etc/ssh/ssh_host_rsa_key permissions are 600 and owned by root:root
If the output does not match the expected result, this is a finding.
M
5323