UCF STIG Viewer Logo
Changes are coming to https://stigviewer.com. Take our survey to help us understand your usage and how we can better serve you in the future.
Take Survey

The operating system, upon successful logon, must display to the user the date and time of the last logon or access via ssh.


Overview

Finding ID Version Rule ID IA Controls Severity
RHEL-06-000507 RHEL-06-000507 RHEL-06-000507_rule Medium
Description
Users need to be aware of activity that occurs regarding their account. Providing users with information regarding the date and time of their last successful login allows the user to determine if any unauthorized activity has occurred and gives them an opportunity to notify administrators. At ssh login, a user must be presented with the last successful login date and time.
STIG Date
Red Hat Enterprise Linux 6 Security Technical Implementation Guide 2013-02-05

Details

Check Text ( C-RHEL-06-000507_chk )
Verify the value associated with the "PrintLastLog" keyword in /etc/ssh/sshd_config:

# grep -I PrintLastLog /etc/sshd_config

If the value is not set to "yes", this is a finding. If the "PrintLastLog" keyword is not present, this is not a finding.
Fix Text (F-RHEL-06-000507_fix)
Update the "PrintLastLog" keyword to "yes" in /etc/ssh/sshd_config:

PrintLastLog yes

While it is acceptable to remove the keyword entirely since the default action for the SSH daemon is to print the last login date and time, it is preferred to have the value explicitly documented.