Rule ID
SV-256387r959010_rule
Version
V1R4
CCIs
CCI-000366
Configuring this setting for the SSH daemon provides additional assurance that remote logon via SSH will require a password, even in the event of misconfiguration elsewhere.
From an ESXi shell, run the following command: # /usr/lib/vmware/openssh/bin/sshd -T|grep permitemptypasswords Expected result: permitemptypasswords no If the output does not match the expected result, this is a finding.
From an ESXi shell, add or correct the following line in "/etc/ssh/sshd_config": PermitEmptyPasswords no