On AIX, the SSH server must not permit root logins using remote access programs.

Severity
Group ID
Group Title
Version
Rule ID
Date
STIG Version
mediumV-215287SRG-OS-000480-GPOS-00227AIX7-00-002102SV-215287r991589_rule2024-08-163
Description
Permitting direct root login reduces auditable information about who ran privileged commands on the system and also allows direct attack attempts on root's password.
ℹ️ Check
Determine if the SSH daemon is configured to disable root logins: # grep -iE "PermitRootLogin[[:blank:]]*no" /etc/ssh/sshd_config | grep -v \# If the above command displays a line, the root login is disabled. If the root login is not disabled, this is a finding.
✔️ Fix
Edit the "/etc/ssh/sshd_config" file to have the following line and save the change: PermitRootLogin no Restart SSH daemon: # stopsrc -s sshd # startsrc -s sshd