Check that the following settings are configured:
$ getsebool -a | grep ssh
allow_ssh_keysign --> off
fenced_can_ssh --> off
sftpd_write_ssh_home --> off
ssh_sysadm_login --> off
ssh_use_gpg_agent --> off
There is a boolean named
ssh_sysadm_login
. This denies a root user from ssh login. Turn on it.
$ setenforce 0
$ setsebool ssh_sysadm_login on
5. root: enforcing and ssh again.
$ setenforce 1
$ ssh root@localhost
Now root user can ssh successfully.
6. root: refer to the audit log.
$ audit2why -a
Figure 19. Audit log for sshd
$ audit2allow -a
NXP Semiconductors
Industrial features
Open Industrial User Guide, Rev. 1.8, 05/2020
User's Guide
67 / 199