RHEL 9 SSH daemon must perform strict mode checking of home directory configuration files.

Severity
Group ID
Group Title
Version
Rule ID
Date
STIG Version
mediumV-258008SRG-OS-000480-GPOS-00227RHEL-09-255160SV-258008r1045075_rule2026-02-052

Description

If other users have access to modify user-specific SSH configuration files, they may be able to log into the system as another user.

ℹ️ Check

Verify the SSH daemon performs strict mode checking of home directory configuration files with the following command: $ sudo /usr/sbin/sshd -dd 2>&1 | awk '/filename/ {print $4}' | tr -d '\r' | tr '\n' ' ' | xargs sudo grep -iH '^\s*strictmodes' StrictModes yes If the "StrictModes" keyword is set to "no", the returned line is commented out, or no output is returned, this is a finding.

✔️ Fix

Configure the SSH daemon to perform strict mode checking of home directory configuration files. Add the following line to "/etc/ssh/sshd_config" or to a file in "/etc/ssh/sshd_config.d", or uncomment the line and set the value to "yes": StrictModes yes The SSH service must be restarted for changes to take effect: $ sudo systemctl restart sshd.service