Check: GEN000452
HP-UX 11.31 STIG:
GEN000452
(in versions v1 r19 through v1 r13)
Title
The system must display the date and time of the last successful account login upon login. (Cat III impact)
Discussion
Providing users with feedback on when account accesses last occurred facilitates user recognition and reporting of unauthorized account use.
Check Content
Check the SSH daemon configuration. Note that keywords are case-insensitive and arguments (args) are case-sensitive. keyword=PrintLastLog Required arg(s)=yes Default arg values include: "yes" Note: When the default "arg" value exactly matches the required "arg" value (see above), the <keyword=arg> are not required to exist (commented or uncommented) in the ssh (client) or sshd (server) configuration file. While not required, it is recommended that the configuration file(s) be populated with all keywords and assigned arg values as a means to explicitly document the ssh(d) binary's expected behavior. Examine the file. # cat /opt/ssh/etc/sshd_config | tr '\011' ' ' | tr -s ' ' | sed -e 's/^[ \t]*//' | grep -v '^#' | grep -i "PrintLastLog" | cut -f 2,2 -d " " If the return value is no, this is a finding.
Fix Text
Edit the configuration file and modify the PrintLastLog line entry as follows: PrintLastLog yes
Additional Identifiers
Rule ID: SV-38302r1_rule
Vulnerability ID: V-22299
Group Title: GEN000452
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000052 |
The information system notifies the user, upon successful logon (access) to the system, of the date and time of the last logon (access). |
Controls
Number | Title |
---|---|
AC-9 |
Previous Logon (Access) Notification |