Why RHEL 9 omit "AcceptEnv LANG" and other locale environment?
Issue
-
In RHEL 9, default
/etc/ssh/sshd_configomit trasfering locale related environment variables. What is the problem in these settings? Are there security issue related with these settings?# Accept locale-related environment variables AcceptEnv LANG LC_CTYPE LC_NUMERIC LC_TIME LC_COLLATE LC_MONETARY LC_MESSAGES AcceptEnv LC_PAPER LC_NAME LC_ADDRESS LC_TELEPHONE LC_MEASUREMENT AcceptEnv LC_IDENTIFICATION LC_ALL LANGUAGE AcceptEnv XMODIFIERS
Environment
- Red Hat Enterprise Linux 9
- openssh
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.