CIS Ubuntu 14.04 LTS - 5.2.1 Ensure permissions on /etc/ssh/sshd_config are configured
Verify /etc/ssh/sshd_config ownership and permissions are restricted to root with no group/other access
Browse reusable Agent Skills, each with a clear purpose and practical guidance.
Verify /etc/ssh/sshd_config ownership and permissions are restricted to root with no group/other access
Verify SSH PermitUserEnvironment is set to no to prevent users from setting environment options
Verify SSH is configured to use only approved MAC algorithms to prevent weak cipher attacks
Verify SSH ClientAliveInterval and ClientAliveCountMax are configured for idle session timeout
Verify SSH LoginGraceTime is set to 60 seconds or less to limit unauthenticated connections
Verify SSH access is limited using AllowUsers, AllowGroups, DenyUsers, or DenyGroups directives
Verify SSH Banner is configured to display a warning message before authentication
Verify SSH is configured to use Protocol version 2 only
Verify SSH LogLevel is configured to INFO for adequate logging of login activity
Verify SSH X11 forwarding is disabled to prevent remote graphic connection tunneling