The Photon operating system must configure Secure Shell (SSH) to disable user environment processing.
Overview
Finding ID | Version | Rule ID | IA Controls | Severity |
V-258871 | PHTN-40-000208 | SV-258871r991591_rule | High |
Description |
Enabling user environment processing may enable users to bypass access restrictions in some configurations and must therefore be disabled. |
STIG | Date |
VMware vSphere 8.0 vCenter Appliance Photon OS 4.0 Security Technical Implementation Guide | 2024-07-11 |
Details
Check Text (C-62611r933672_chk) |
At the command line, run the following command to verify the running configuration of sshd: # sshd -T|&grep -i PermitUserEnvironment Example result: permituserenvironment no If "PermitUserEnvironment" is not set to "no", this is a finding. |
Fix Text (F-62520r933673_fix) |
Navigate to and open: /etc/ssh/sshd_config Ensure the "PermitUserEnvironment" line is uncommented and set to the following: PermitUserEnvironment no At the command line, run the following command: # systemctl restart sshd.service |