openSSH 9.8 - SC-05 #58

Closed
opened 2026-01-19 18:29:05 +00:00 by michael · 3 comments
Owner

Originally created by @robertgendler on GitHub.

Originally assigned to: @robertgendler on GitHub.

Configuring persourcepenalties to meet SC-05

Originally created by @robertgendler on GitHub. Originally assigned to: @robertgendler on GitHub. Configuring persourcepenalties to meet SC-05
Author
Owner

@robertgendler commented on GitHub:

create check to make sure PerSourcePenalties is not set to no.

@robertgendler commented on GitHub: create check to make sure PerSourcePenalties is not set to no.
Author
Owner

@robertgendler commented on GitHub:

fix set PerSourcePenalties to yes

@robertgendler commented on GitHub: fix set PerSourcePenalties to yes
Author
Owner

@snoopy82481 commented on GitHub:

Check command and if not true it is a finding.

sshd -G | grep -q 'persourcepenalties crash:90 authfail:5 noauth:1 grace-exceeded:20 max:600 min:15 max-sources4:65536 max-sources6:65536 overflow:permissive overflow6:permissive' && echo "true" || echo "false"
@snoopy82481 commented on GitHub: Check command and if not `true` it is a finding. ```bash sshd -G | grep -q 'persourcepenalties crash:90 authfail:5 noauth:1 grace-exceeded:20 max:600 min:15 max-sources4:65536 max-sources6:65536 overflow:permissive overflow6:permissive' && echo "true" || echo "false" ```
Sign in to join this conversation.
No Label
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: usnistgov/macos_security#58