Skill v2.2.0
currentAutomated scan100/100name: cis-ubuntu1804-v220-4-2-10 description: "Ensure sshd IgnoreRhosts is enabled" category: cis-networking version: "2.2.0" author: cyberstrike-official tags: [cis, ubuntu, linux, ubuntu-18.04, ssh, remote-access] cis_id: "4.2.10" cis_benchmark: "CIS Ubuntu Linux 18.04 LTS Benchmark v2.2.0" tech_stack: [ubuntu, linux] cwe_ids: [] chains_with: [] prerequisites: [] severity_boost: {}
CIS Ubuntu Linux 18.04 LTS Benchmark v2.2.0 - Control 4.2.10
Profile Applicability
- Level 1 - Server
- Level 1 - Workstation
Description
The IgnoreRhosts parameter specifies that .rhosts and .shosts files will not be used in RhostsRSAAuthentication or HostbasedAuthentication.
Rationale
Setting this parameter forces users to enter a password when authenticating with SSH.
Audit Procedure
Command Line
Run the following command and verify the output:
sshd -T | grep -i ignorerhosts
Expected Result
ignorerhosts yes
Remediation
Command Line
Edit the /etc/ssh/sshd_config file to set the parameter as follows:
IgnoreRhosts yes
Default Value
IgnoreRhosts yes
References
- NIST SP 800-53 Rev. 5: CM-7
CIS Controls
v8 - 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software.
v7 - 9.2 Ensure Only Approved Ports, Protocols, and Services Are Running.
Profile Applicability
- Level 1 - Server
- Level 1 - Workstation
Assessment Status
Automated