AlmaLinux OS 9 SSH daemon must display the date and time of the last successful account logon upon an SSH logon.

STIG ID: ALMA-09-021250  |  SRG: SRG-OS-000480-GPOS-00227 |  Severity: medium |  CCI: CCI-000366 |  Vulnerability Id: V-269268

Vulnerability Discussion

Providing users feedback on when account accesses last occurred facilitates user recognition and reporting of unauthorized account use.

Check

Verify the SSH daemon provides users with feedback on when account accesses last occurred with the following command:

$ sshd -T | grep printlastlog

printlastlog yes

If the value is returned as "no", this is a finding.

Fix

Configure the SSH daemon to provide users with feedback on when account accesses last occurred.

Add the following line to "/etc/ssh/sshd_config", or uncomment the line and set the value to "yes":

PrintLastLog yes

Alternatively, add the setting to an include file if the line "Include /etc/ssh/sshd_config.d/*.conf" is found at the top of the "/etc/ssh/sshd_config" file:

$ echo 'PrintLastLog yes' > /etc/ssh/sshd_config.d/40-lastlog.conf

Restart the SSH daemon for the settings to take effect:

$ systemctl restart sshd.service