Skip to content

Commit

Permalink
Merge pull request #12667 from mpurg/ubuntu2404_cis_5_1_16
Browse files Browse the repository at this point in the history
Add rules and vars to ubuntu2404 CIS control 5.1.16
  • Loading branch information
dodys authored Dec 4, 2024
2 parents edcb42a + ee5a620 commit e58e9aa
Show file tree
Hide file tree
Showing 4 changed files with 29 additions and 3 deletions.
5 changes: 2 additions & 3 deletions controls/cis_ubuntu2404.yml
Original file line number Diff line number Diff line change
Expand Up @@ -1683,11 +1683,10 @@ controls:
levels:
- l1_server
- l1_workstation
related_rules:
rules:
- sshd_max_auth_tries_value=4
- sshd_set_max_auth_tries
status: planned
notes: TODO. Partial/incorrect implementation exists.See related rules. Analogous to ubuntu2204/5.2.18.
status: automated

- id: 5.1.17
title: Ensure sshd MaxSessions is configured (Automated)
Expand Down
Original file line number Diff line number Diff line change
@@ -0,0 +1,9 @@
# platform = multi_platform_all
# variables = sshd_max_auth_tries_value=4
SSHD_CONFIG="/etc/ssh/sshd_config"

if grep -q "^MaxAuthTries" $SSHD_CONFIG; then
sed -i "s/^MaxAuthTries.*/MaxAuthTries 4/" $SSHD_CONFIG
else
echo "MaxAuthTries 4" >> $SSHD_CONFIG
fi
Original file line number Diff line number Diff line change
@@ -0,0 +1,9 @@
# platform = multi_platform_all
# variables = sshd_max_auth_tries_value=4
SSHD_CONFIG="/etc/ssh/sshd_config"

if grep -q "^MaxAuthTries" $SSHD_CONFIG; then
sed -i "s/^MaxAuthTries.*/MaxAuthTries 0/" $SSHD_CONFIG
else
echo "MaxAuthTries 0" >> $SSHD_CONFIG
fi
Original file line number Diff line number Diff line change
@@ -0,0 +1,9 @@
# platform = multi_platform_all
# variables = sshd_max_auth_tries_value=4
SSHD_CONFIG="/etc/ssh/sshd_config"

if grep -q "^MaxAuthTries" $SSHD_CONFIG; then
sed -i "s/^MaxAuthTries.*/MaxAuthTries 1000/" $SSHD_CONFIG
else
echo "MaxAuthTries 1000" >> $SSHD_CONFIG
fi

0 comments on commit e58e9aa

Please sign in to comment.