blob: d9e3b7b649c99555091ce1866a824871a6c675a9 [file] [log] [blame]
# 5.2.4 Ensure SSH X11 forwarding is disabled (Scored)
#
# Profile Applicability
# ---------------------
# - Level 1 - Server
# - Level 1 - Workstation
#
# Description
# -----------
# The X11Forwarding parameter provides the ability to tunnel X11 traffic through the
# connection to enable remote graphic connections.
#
# Rationale
# ---------
# Disable X11 forwarding unless there is an operational requirement to use X11 applications
# directly. There is a small risk that the remote X11 servers of users who are logged in via
# SSH with X11 forwarding could be compromised by other users on the X11 server. Note
# that even if X11 forwarding is disabled, users can always install their own forwarders.
#
# Audit
# -----
# Run the following command and verify that output matches:
#
# # grep "^X11Forwarding" /etc/ssh/sshd_config
# X11Forwarding no
#
# Remediation
# -----------
# Edit the /etc/ssh/sshd_config file to set the parameter as follows:
#
# X11Forwarding no
parameters:
openssh:
server:
x11:
forwarding: False