UCF STIG Viewer Logo

The macOS system must require individuals to be authenticated with an individual authenticator prior to using a group authenticator.


Finding ID Version Rule ID IA Controls Severity
V-225158 AOSX-15-001100 SV-225158r610901_rule Medium
Administrator users must never log in directly as root. To assure individual accountability and prevent unauthorized access, logging in as root over a remote connection must be disabled. Administrators should only run commands as root after first authenticating with their individual user names and passwords.
Apple OS X 10.15 (Catalina) Security Technical Implementation Guide 2021-11-19


Check Text ( C-26857r467642_chk )
To check if SSH has root logins enabled, run the following command:

/usr/bin/sudo /usr/bin/grep ^PermitRootLogin /etc/ssh/sshd_config

If there is no result, or the result is set to "yes", this is a finding.
Fix Text (F-26845r467643_fix)
To ensure that "PermitRootLogin" is disabled by sshd, run the following command:

/usr/bin/sudo /usr/bin/sed -i.bak 's/^[\#]*PermitRootLogin.*/PermitRootLogin no/' /etc/ssh/sshd_config