CIS Ubuntu 14.04 LTS - 5.2.5 Ensure SSH MaxAuthTries is set to 4 or less
Verify SSH MaxAuthTries is set to 4 or less to limit brute force attack risk
Browse reusable Agent Skills, each with a clear purpose and practical guidance.
Verify SSH MaxAuthTries is set to 4 or less to limit brute force attack risk
Verify SSH IgnoreRhosts is set to yes to prevent .rhosts-based authentication
Verify SSH HostbasedAuthentication is disabled to prevent host-based trust authentication
Verify SSH PermitRootLogin is set to no to prevent direct root login over SSH
Verify SSH PermitEmptyPasswords is set to no to prevent login with empty passwords
Verify PAM is configured to lock out users after repeated failed password attempts
Verify PAM is configured to remember at least 5 previous passwords to prevent reuse
Verify PAM is configured to use SHA-512 hashing algorithm for password storage
Verify PASS_MAX_DAYS is set to 365 or less in /etc/login.defs for password expiration
Verify PASS_MIN_DAYS is set to 7 or more in /etc/login.defs to prevent rapid password cycling