Direct root account login must not be permitted for SSH access.
Severity | Group ID | Group Title | Version | Rule ID | Date | STIG Version |
---|---|---|---|---|---|---|
medium | V-216117 | SRG-OS-000480 | SOL-11.1-040360 | SV-216117r959010_rule | 2024-11-25 | 3 |
Description |
---|
The system should not allow users to log in as the root user directly, as audited actions would be non-attributable to a specific user. |
ℹ️ Check |
---|
Determine if root login is disabled for the SSH service. # grep "^PermitRootLogin" /etc/ssh/sshd_config If the output of this command is not: PermitRootLogin no this is a finding. |
✔️ Fix |
---|
The root role is required. Modify the sshd_config file # pfedit /etc/ssh/sshd_config Locate the line containing: PermitRootLogin Change it to: PermitRootLogin no Restart the SSH service. # svcadm restart svc:/network/ssh |