UCF STIG Viewer Logo

Direct root account login must not be permitted for SSH access.


Overview

Finding ID Version Rule ID IA Controls Severity
V-48103 SOL-11.1-040360 SV-60975r1_rule Medium
Description
The system should not allow users to log in as the root user directly, as audited actions would be non-attributable to a specific user.
STIG Date
Solaris 11 SPARC Security Technical Implementation Guide 2017-04-28

Details

Check Text ( None )
None
Fix Text (F-51713r1_fix)
The root role is required.

Modify the sshd_config file

# pfedit /etc/ssh/sshd_config

Locate the line containing:

PermitRootLogin

Change it to:

PermitRootLogin no

Restart the SSH service.

# svcadm restart svc:/network/ssh