audit-labs/audit-tools

A collection of scripts, queries, and other goodies you can use in an audit. audit automation compliance evidence scripts

Commit 9099dc94d2

9099dc94d2431094ee480c3837459b130ad0ab3c

parent: a6b093b3f5

Unsigned

cmc <hello@cleberg.net> · 2025-12-12 17:21 UTC
committer: <noreply@github.com>

add logic for handling explicit and implicit root keys files

Layout: unified · split

os/linux/ssh_root_login.sh +53 −7
@@ -1,15 +1,61 @@
11#!/bin/bash
22
3# Find the PermitRootLogin setting in the sshd_config file
3# Check if the sshd_config file exists
4if [ ! -f /etc/ssh/sshd_config ]; then
5 echo "Error: /etc/ssh/sshd_config not found."
6 exit 1
7fi
8
9echo "--- SSH Root Login Audit ---"
10
11# Find the PermitRootLogin setting, ignoring commented-out lines
412permit_root_login=$(grep -E "^[[:space:]]*PermitRootLogin" /etc/ssh/sshd_config)
513
6# Echo the setting for the user
7echo "Current PermitRootLogin setting:"
8echo "$permit_root_login"
14if [ -z "$permit_root_login" ]; then
15 echo "PermitRootLogin is not explicitly set. Relying on sshd defaults (usually 'prohibit-password')."
16 # In this case, we can assume it's not a simple 'yes', so we can stop.
17 exit 0
18else
19 echo "Found setting: $permit_root_login"
20fi
21
922
1023# Check if PermitRootLogin is set to something other than 'no'
1124if ! echo "$permit_root_login" | grep -q "no"; then
12 echo ""
13 echo "PermitRootLogin is not set to 'no'. Checking for AuthorizedKeysFile location..."
14 grep -E "^[[:space:]]*AuthorizedKeysFile" /etc/ssh/sshd_config
25 echo "[WARNING] Root login is permitted."
26 echo ""
27 echo "Checking for root's authorized_keys file..."
28
29 # Look for an explicitly set AuthorizedKeysFile path
30 auth_keys_path_line=$(grep -E "^[[:space:]]*AuthorizedKeysFile" /etc/ssh/sshd_config)
31
32 if [ -n "$auth_keys_path_line" ]; then
33 # An explicit path is set. Extract the path.
34 # This removes the 'AuthorizedKeysFile' keyword and leading/trailing whitespace.
35 auth_keys_path=$(echo "$auth_keys_path_line" | awk '{print $2}')
36 echo "sshd_config specifies: $auth_keys_path_line"
37
38 # The path might contain '%h', which means the user's home directory.
39 # For root, this is /root.
40 actual_path=${auth_keys_path/\%h/\/root}
41
42 else
43 # No explicit path is set, so we check the default location.
44 echo "AuthorizedKeysFile not set in sshd_config. Checking default location."
45 actual_path="/root/.ssh/authorized_keys"
46 fi
47
48 echo "Checking for file at: $actual_path"
49 if [ -f "$actual_path" ]; then
50 echo "[CRITICAL] Found authorized keys file for root at $actual_path"
51 echo "Contents:"
52 echo "----------------------------------------"
53 cat "$actual_path"
54 echo "----------------------------------------"
55 else
56 echo "[INFO] No authorized keys file found at the specified or default location."
57 fi
58
59else
60 echo "[OK] PermitRootLogin is set to 'no'. No further checks needed."
1561fi