This is not the latest version of the STIG. This is provided for archival purposes. See the latest STIG.

RHEL 10 must not have any ".shosts" files on the system.

STIG ID: RHEL-10-700690  |  SRG: SRG-OS-000080-GPOS-00048 |  Severity: medium (CAT II)  |  CCI: CCI-000213 |  Vulnerability Id: V-281272

Vulnerability Discussion

The ".shosts" files are used to configure host-based authentication for individual users or the system via Secure Shell (SSH). Host-based authentication is not sufficient for preventing unauthorized access to the system, as it does not require interactive identification and authentication of a connection request, or for the use of two-factor authentication.

Check

Verify RHEL 10 does not have any ".shosts" files on the system with the following command:

$ sudo find / -name .shosts

If a ".shosts" file is found, this is a finding.

Fix

Configure RHEL 10 to not have any ".shosts" files on the system.

Remove any found ".shosts" files from the system with the following command:

$ sudo rm /[path]/[to]/[file]/.shosts