Check: RHEL-06-000507
Red Hat Enterprise Linux 6 STIG:
RHEL-06-000507
(in versions v2 r2 through v1 r14)
Title
The operating system, upon successful logon, must display to the user the date and time of the last logon or access via ssh. (Cat II impact)
Discussion
Users need to be aware of activity that occurs regarding their account. Providing users with information regarding the date and time of their last successful login allows the user to determine if any unauthorized activity has occurred and gives them an opportunity to notify administrators. At ssh login, a user must be presented with the last successful login date and time.
Check Content
Verify the value associated with the "PrintLastLog" keyword in /etc/ssh/sshd_config: # grep -i "^PrintLastLog" /etc/ssh/sshd_config If the "PrintLastLog" keyword is not present, this is not a finding. If the value is not set to "yes", this is a finding.
Fix Text
Update the "PrintLastLog" keyword to "yes" in /etc/ssh/sshd_config: PrintLastLog yes While it is acceptable to remove the keyword entirely since the default action for the SSH daemon is to print the last logon date and time, it is preferred to have the value explicitly documented.
Additional Identifiers
Rule ID: SV-218090r603264_rule
Vulnerability ID: V-218090
Group Title: SRG-OS-000025
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000052 |
Notify the user, upon successful logon (access) to the system, of the date and time of the last logon (access). |
Controls
Number | Title |
---|---|
AC-9 |
Previous Logon (access) Notification |