STIGUI
V-282713CAT II — Medium severitySV-282713r1201377_rule

The TOSS 5 SSH daemon must perform strict mode checking of home directory configuration files.

Rule version TOSS-05-000259 · STIG v1 · 2026-08-20

Discussion

If other users have access to modify user-specific SSH configuration files, they may be able to log into the system as another user.

Check

Verify the SSH daemon performs strict mode checking of home directory configuration files using the following command:

$ sudo /usr/sbin/sshd -dd 2>&1 | awk '/filename/ {print $4}' | tr -d '\r' | tr '\n' ' ' | xargs sudo grep -iH '^\s*strictmodes'

StrictModes yes

If the "StrictModes" keyword is set to "no", the returned line is commented out, or no output is returned, this is a finding.

Fix

Configure the SSH daemon to perform strict mode checking of home directory configuration files.

Add the following line in "/etc/ssh/sshd_config" or uncomment the line and set the value to "yes":

StrictModes yes

Restart the SSH service for changes to take effect:

$ sudo systemctl restart sshd.service

Identifiers

Group ID
V-282713
Group title
SRG-OS-000480-GPOS-00227
Rule ID
SV-282713r1201377_rule
Check ID
C-87274r1201117_chk
Fix ID
F-87179r1201376_fix