Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-214877 | AOSX-13-000565 | SV-214877r507075_rule | Medium |
Description |
---|
Administrators must never log in directly as root. To assure individual accountability and prevent unauthorized access, logging in as root over a remote connection must be disabled. Administrators should only run commands as root after first authenticating with their individual user names and passwords. |
STIG | Date |
---|---|
Apple OS X 10.13 Security Technical Implementation Guide | 2020-09-11 |
Check Text ( C-16077r397203_chk ) |
---|
To check if SSH has root logins enabled, run the following command: /usr/bin/sudo /usr/bin/grep ^PermitRootLogin /etc/ssh/sshd_config If there is no result, or the result is set to "yes", this is a finding. |
Fix Text (F-16075r397204_fix) |
---|
To ensure that "PermitRootLogin" is disabled by sshd, run the following command: /usr/bin/sudo /usr/bin/sed -i.bak 's/^[\#]*PermitRootLogin.*/PermitRootLogin no/' /etc/ssh/sshd_config |