AlmaLinux OS 9 SSH daemon must display the date and time of the last successful account logon upon an SSH logon.

Severity
Group ID
Group Title
Version
Rule ID
Date
STIG Version
mediumV-269268SRG-OS-000480-GPOS-00227ALMA-09-021250SV-269268r1050150_rule2025-02-201
Description
Providing users feedback on when account accesses last occurred facilitates user recognition and reporting of unauthorized account use.
ℹ️ Check
Verify the SSH daemon provides users with feedback on when account accesses last occurred with the following command: $ sshd -T | grep printlastlog printlastlog yes If the value is returned as "no", this is a finding.
✔️ Fix
Configure the SSH daemon to provide users with feedback on when account accesses last occurred. Add the following line to "/etc/ssh/sshd_config", or uncomment the line and set the value to "yes": PrintLastLog yes Alternatively, add the setting to an include file if the line "Include /etc/ssh/sshd_config.d/*.conf" is found at the top of the "/etc/ssh/sshd_config" file: $ echo 'PrintLastLog yes' > /etc/ssh/sshd_config.d/40-lastlog.conf Restart the SSH daemon for the settings to take effect: $ systemctl restart sshd.service