You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
sshd_set_keepalive is misaligned with DISA's xccdf_mil.disa.stig_rule_SV-257995r970703_rule.
Content uses distributed config and puts it to different file than DISA expects.
For SSG, the rule passes, because it finds remediated ClientAliveCountMax 1 in /etc/ssh/sshd_config.d/00-complianceascode-hardening.conf
DISA fails, because it searches only for ClientAliveCountMax 1 in /etc/ssh/sshd_config file.
SCAP Security Guide Version:
latest master
Operating System Version:
RHEL 9
Actual Results:
SSG and DISA rules are misaligned.
Expected Results:
SSG is aligned with DISA.
The text was updated successfully, but these errors were encountered:
We are out of aliment based the text "If "ClientAliveCountMax" does not exist, is not set to a value of "1" in "/etc/ssh/sshd_config", or is commented out, this is a finding."
The STIG requires it to be in the main file, not drop in files
Description of problem:
sshd_set_keepalive
is misaligned with DISA'sxccdf_mil.disa.stig_rule_SV-257995r970703_rule
.Content uses distributed config and puts it to different file than DISA expects.
For SSG, the rule passes, because it finds remediated
ClientAliveCountMax 1
in/etc/ssh/sshd_config.d/00-complianceascode-hardening.conf
DISA fails, because it searches only for
ClientAliveCountMax 1
in/etc/ssh/sshd_config
file.SCAP Security Guide Version:
latest master
Operating System Version:
RHEL 9
Actual Results:
SSG and DISA rules are misaligned.
Expected Results:
SSG is aligned with DISA.
The text was updated successfully, but these errors were encountered: