Lynis Security Controls

SSH-7408 - SSH configuration

Description

Proper hardening of your SSH configuration can reduce known weaknesses

Group

SSH

How to solve

The secure shell, or SSH, is one of the most used services. Nearly all machines have a SSH daemon running, to allow system administrators connect and manage the system. SSH is not limited to interactive system administration via the shell. Things like backups, remote configuration, and data transfers are common other uses as well.

Since SSH has an important function on the system, and firewalls are often opened up to allow traffic, proper hardening of the service is needed. Lynis checks for several key options and helps to avoid weak configurations. With every system having a different role, the right combination of settings needs to be configured.

Harden your SSH configuration with the specified configuration option listed in the Lynis output. Consult the SSH documentation for the meaning of each option, and select the best possible option for your system. Where possible choose the most strict option, to increase your security defenses.

The specific configuration settings to harden are listed in the log file (/var/log/lynis.log) and your report file (/var/log/lynis-report.dat).

Notes

TCP forwarding

A note from the SSH man page: Note that disabling TCP forwarding does not improve security unless users are also denied shell access, as they can always install their own forwarders.

Additional resources

Perform daily health checks of your environment, learn in-depth system hardening, and protect your systems better.

Upgrade to Lynis Enterprise

Linux and Unix System Hardening

This information is provided as part of the Lynis community project. It is related to Lynis control SSH-7408. All information should be considered as-is, without guarantees. Any advice or snippets should be tested before implementing in production environments.

Lynis

Lynis is a technical security audit tool for Unix flavors like Linux, macOS, AIX, Solaris, and *BSD. It is open source software and free to use. The project has an active community, including open development via GitHub.

Lynis Enterprise

Need more advanced features, like vulnerability scanning, or reporting installed software packages? Lynis Enterprise will collect more data and present it with an easy to use web interface.

Gain additional benefits: automating security audits, reporting, and the implementation of related security measures.

Lynis Enterprise includes
  • Centralized management
  • Prioritized plans
  • Reporting
  • Dashboards
  • Integration (API)
  • Improvement snippets for tools like Ansible, Chef, Cfengine, Puppet, and SaltStack

Take the Tour