The operating system must terminate all sessions and network connections when nonlocal maintenance is completed.
Overview
| Finding ID | Version | Rule ID | IA Controls | Severity |
| V-216162 | SOL-11.1-050460 | SV-216162r986457_rule | CCI-001133 | medium |
| Description | ||||
| Nonlocal maintenance and diagnostic activities are those activities conducted by individuals communicating through a network, either an external network (e.g., the internet) or an internal network. The operating system needs to ensure all sessions and network connections are terminated when nonlocal maintenance is completed. | ||||
| STIG | Date | |||
| Solaris 11 X86 Security Technical Implementation Guide | 2025-05-05 | |||
Details
Check Text (C-216162r986457_chk)
Determine if SSH is configured to disconnect sessions after 10 minutes of inactivity.
# grep ClientAlive /etc/ssh/sshd_config
If the output of this command is not as shown below, this is a finding.
ClientAliveInterval 600
ClientAliveCountMax 0
Fix Text (F-17398r372869_fix)
The root role is required.
Configure the system to disconnect SSH sessions after 10 minutes of inactivity.
# pfedit /etc/ssh/sshd_config
Insert the two lines:
ClientAliveInterval 600
ClientAliveCountMax 0
Restart the SSH service with the new configuration.
# svcadm restart svc:/network/ssh