Problems with ssh connection for a remote assessment

Problems with ssh connection for a remote assessment

Product Name

CIS-CAT Pro Assessor v4

Product Version



Jan 20, 2021



The remote assessment ssh connection will be successful but commands will error out.

There will be errors in assessor-cli.log - sudo: no tty present and no askpass program specified



The problem is caused by a setting on the target system in /etc/sudoers -  Defaults requiretty

You can comment that line out or, disable it for the sudo user that is defined in CISCAT sessions.properties.

In this example, carlos is the user configured for the ssh remote assessment. So we can add this additional line to /etc/sudoers which will disable requiretty for sudo user carlos;

 Defaults:carlos !requiretty

Note that if you are using a key to connect to the target it is possible that a password is required for the user to use sudo on the target system.

If you are using a key there are 2 possible solutions.

  1. Change /etc/sudoers on the target so a password is not needed to sudo for that specific user. If the user is carlos then the entry in /etc/sudoers will be; carlos ALL=(root) NOPASSWD:ALL

  2. Or, you will need to add the sudo password to config/sessions.properties. In the example below the session.2.cred section of sessions.properties has the password required for sudo. You can then encrypt the contents of sessions.properties so that password is hidden. Please see this section of the documentation for information on encrypting and decrypting that file.


The ssh key needs to be in PEM format i.e. the header of your key file will be;



Related Content

Copyright © 2020

Center for Internet Security®


Related content

Setting up ssh keys for remote CIS-CAT assessment
Setting up ssh keys for remote CIS-CAT assessment
More like this
Quick Start Guide: CIS-CAT Remote Linux Scanning From a Windows Host
Quick Start Guide: CIS-CAT Remote Linux Scanning From a Windows Host
More like this
I cannot produce HTML reports from the Command line (Assessor-CLI)
I cannot produce HTML reports from the Command line (Assessor-CLI)
Read with this
Diagnostic / debug information to troubleshoot CIS-CAT Pro Assessor v4 issues.
Diagnostic / debug information to troubleshoot CIS-CAT Pro Assessor v4 issues.
Read with this
Differing Results between Local and Remote Linux Assessment
Differing Results between Local and Remote Linux Assessment
More like this