The ESXi host Secure Shell (SSH) daemon must set a timeout count on idle sessions.

Overview

Finding IDVersionRule IDIA ControlsSeverity
V-256394ESXI-70-000026SV-256394r959010_ruleCCI-000366low
Description
Setting a timeout ensures that a user login will be terminated as soon as the "ClientAliveCountMax" is reached.
STIGDate
VMware vSphere 7.0 ESXi Security Technical Implementation Guide2025-02-11

Details

Check Text (C-256394r959010_chk)

From an ESXi shell, run the following command: # /usr/lib/vmware/openssh/bin/sshd -T|grep clientalivecountmax Expected result: clientalivecountmax 3 If the output does not match the expected result, this is a finding.

Fix Text (F-60012r885962_fix)

From an ESXi shell, add or correct the following line in "/etc/ssh/sshd_config": ClientAliveCountMax 3