STIGUI
V-285321CAT II — Medium severitySV-285321r1268251_rule

Windows Server 2025 OpenSSH private host key files must conform to minimum requirements.

Rule version WN25-SH-000090 · STIG v1 · 2026-09-01

Discussion

If an unauthorized user obtains the private SSH host key file, the host could be impersonated.

Check

If OpenSSH is not installed on the system, this requirement is not applicable.

Verify the SSH private host key files permissions with the following command:

C:\ > Get-ChildItem -Path "C:\ProgramData\ssh" -Filter "*_key" -File | ForEach-Object { icacls.exe $_.FullName }

C:\ProgramData\ssh\ssh_host_ecdsa_key BUILTIN\Administrators:(F) NT AUTHORITY\SYSTEM:(F)

Successfully processed 1 files; Failed processing 0 files C:\ProgramData\ssh\ssh_host_ed25519_key BUILTIN\Administrators:(F) NT AUTHORITY\SYSTEM:(F)

Successfully processed 1 files; Failed processing 0 files C:\ProgramData\ssh\ssh_host_rsa_key BUILTIN\Administrators:(F) NT AUTHORITY\SYSTEM:(F)

Successfully processed 1 files; Failed processing 0 files

If any private host key file does not have the default permission as in the example output, this is a finding.

Fix

Maintain the permissions of the private host key files as follows:

BUILTIN\Administrators:(F) NT AUTHORITY\SYSTEM:(F)

Identifiers

Group ID
V-285321
Group title
SRG-OS-000480-GPOS-00227
Rule ID
SV-285321r1268251_rule
Check ID
C-89891r1211189_chk
Fix ID
F-89796r1211190_fix