Vulnerability Discussion
Providing users feedback on when account accesses last occurred facilitates user recognition and reporting of unauthorized account use.
Check
Verify the SSH daemon provides users with feedback on when account accesses last occurred with the following command:
$ sshd -T | grep printlastlog
printlastlog yes
If the value is returned as "no", this is a finding.
Fix
Configure the SSH daemon to provide users with feedback on when account accesses last occurred.
Add the following line to "/etc/ssh/sshd_config", or uncomment the line and set the value to "yes":
PrintLastLog yes
Alternatively, add the setting to an include file if the line "Include /etc/ssh/sshd_config.d/*.conf" is found at the top of the "/etc/ssh/sshd_config" file:
$ echo 'PrintLastLog yes' > /etc/ssh/sshd_config.d/40-lastlog.conf
Restart the SSH daemon for the settings to take effect:
$ systemctl restart sshd.service