LOW RHCOS (Node) L1: SSHD LogLevel P4

PASS (vanilla RHCOS 9.8+) Scanned: 2026-08-12 Synced: 2026-06-30
SSHD LogLevel is already set to INFO by default in RHCOS 10.2 (OCP 5.0). No MachineConfig needed. OCP 4.22 and earlier still require remediation.

No remediation needed on RHCOS 10.2+ (OCP 5.0+). These checks PASS on vanilla RHCOS 10.2 due to hardened OS defaults shipped in that version. Older RHCOS versions (9.6 and earlier) still require remediation. Verified with compliance-operator v1.8.2 and pinned content quay.io/bapalm/k8scontent:v0.1.80.

Overview

This remediation configures the SSH daemon logging level to INFO, ensuring adequate logging of SSH connections and authentication events.

Settings

Setting Value Description
LogLevel INFO Set SSH logging to INFO level

Log Level Options

Level Description
QUIET Minimal logging
FATAL Only fatal errors
ERROR Errors only
INFO Informational messages (recommended)
VERBOSE Detailed logging
DEBUG Debug information (not for production)

Implementation

The remediation applies a MachineConfig with SSHD logging configuration:

apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
metadata:
  name: 75-sshd-low
  labels:
    machineconfiguration.openshift.io/role: master
spec:
  config:
    ignition:
      version: 3.2.0
    storage:
      files:
        - path: /etc/ssh/sshd_config.d/75-low-hardening.conf
          mode: 0600
          overwrite: true
          contents:
            inline: |
              # LOW severity SSHD settings
              LogLevel INFO

Compliance Checks Remediated

Check Profile Docs
rhcos4-e8-worker-sshd-set-loglevel-info E8 📖
rhcos4-e8-master-sshd-set-loglevel-info E8 📖

Source Remediation Files

  • low/rhcos4-e8-worker-sshd-set-loglevel-info.yaml
  • low/rhcos4-e8-master-sshd-set-loglevel-info.yaml

Verification

After applying the MachineConfig, verify SSHD logging:

oc debug node/<node-name> -- chroot /host sshd -T | grep loglevel
# Expected output: loglevel INFO

Other SSHD hardening groups:

Legend
Remediation Status
✅ PASS (vanilla) Passes on unhardened RHCOS; no remediation needed
🟢 Verified Remediation tested on live cluster, confirmed PASS
🔵 In Progress Remediation actively being developed or tested
🟡 Pending Not yet started; needs remediation work
🟠 Partial Some checks pass or remediation not fully validated
⚪ On Hold Work paused (blocked or deprioritized)
Upstream Verdict
🔼 Candidate Suitable for upstreaming to ComplianceAsCode
🟣 PR Open Upstream PR filed
🎯 RAN Only Only applies to RAN deployments
⚙️ Platform Requires OCP platform-level configuration
✅ Pass Already passing upstream
📍 Site Site/deployment-specific configuration
— N/A Not applicable for upstreaming
Platform
RHCOS Node-level checks (MachineConfig)
OCP Platform-level checks (API/CR)
Mixed Both RHCOS and OCP checks
Severity
HIGH
MEDIUM
LOW
MANUAL

Keyboard Shortcuts

Navigation
j / Next row
k / Previous row
Enter Open selected / Expand details
Esc Clear selection / Close modal
Actions
/ Focus search
d Toggle dark mode
? Show this help
g h Go to home
Filters
1 Show all
2 Pending only
3 In Progress only
4 Complete only