audit-labs/audit-tools

A collection of scripts, queries, and other goodies you can use in an audit. audit automation compliance evidence scripts

Commit 72182b8b3b

72182b8b3b809ecd334d7e4d7c442fb66c61c817

parent: edef45d70c

Unsigned

cmc <hello@cleberg.net> · 2025-12-12 18:06 UTC
committer: <noreply@github.com>

Implement root check and enhance error messages

Added root check and improved error handling for SSH root login script.

Layout: unified · split

os/linux/ssh_root_login.sh +14 −1
@@ -1,5 +1,11 @@
1#!/bin/bash 1#!/bin/bash
2 2
3# Check if the script is being run as root
4if [ "$EUID" -ne 0 ]; then
5 echo "Error: This script must be run as root or with sudo."
6 exit 1
7fi
8
3# Check if the sshd_config file exists 9# Check if the sshd_config file exists
4if [ ! -f /etc/ssh/sshd_config ]; then 10if [ ! -f /etc/ssh/sshd_config ]; then
5 echo "Error: /etc/ssh/sshd_config not found." 11 echo "Error: /etc/ssh/sshd_config not found."
@@ -10,7 +16,14 @@ echo "--- SSH Root Login Audit ---"
10 16
11# Find the PermitRootLogin setting, ignoring commented-out lines 17# Find the PermitRootLogin setting, ignoring commented-out lines
12permit_root_login=$(grep -E "^[[:space:]]*PermitRootLogin" /etc/ssh/sshd_config) 18permit_root_login=$(grep -E "^[[:space:]]*PermitRootLogin" /etc/ssh/sshd_config)
13echo "Found setting: $permit_root_login" 19
20if [ -z "$permit_root_login" ]; then
21 echo "PermitRootLogin is not explicitly set. Relying on sshd defaults (usually 'prohibit-password')."
22 # In this case, we can assume it's not a simple 'yes', so we can stop.
23 exit 0
24else
25 echo "Found setting: $permit_root_login"
26fi
14 27
15 28
16# Check if PermitRootLogin is set to something other than 'no' 29# Check if PermitRootLogin is set to something other than 'no'