UCF STIG Viewer Logo
Changes are coming to https://stigviewer.com. Take our survey to help us understand your usage and how we can better serve you in the future.
Take Survey

The operating system must require individuals to be authenticated with an individual authenticator prior to using a group authenticator.


Overview

Finding ID Version Rule ID IA Controls Severity
V-58361 AOSX-09-000565 SV-72791r1_rule Medium
Description
Administrator users must never log in directly as root. To assure individual accountability and prevent unauthorized access, logging in as root over a remote connection must be disabled. Administrators should only run commands as root after first authenticating with their individual user names and passwords.
STIG Date
Apple OS X 10.9 (Mavericks) Workstation Security Technical Implementation Guide 2017-01-05

Details

Check Text ( C-59187r1_chk )
To check if SSH has root logins enabled, run the following command:

sudo grep ^PermitRootLogin /etc/sshd_config

If there is no result, or the result is set to 'yes', this is a finding.
Fix Text (F-63677r1_fix)
In order to make sure that PermitRootLogin is disabled by sshd, run the following command:

sudo sed -i.bak 's/^[\#]*PermitRootLogin.*/PermitRootLogin no/' /etc/sshd_config