Configure Accepting Prefix Information in Router Advertisements on All IPv6 Interfaces
Sets net.ipv6.conf.all.accept_ra_pinfo to 0 so the host ignores Prefix Information Options carried in IPv6 Router Advertisements on all interfaces.
Checked against the resolved running state (e.g. sshd -T, sysctl, systemctl show), catches drop-ins and Includes a file read would miss. Caveat: runtime ≠ persistence; a value correct now may not survive a reboot.
Pavois asserts the effective configuration, the live, resolved state, not a file. File-based scanners (OVAL/SCAP, Lynis) miss Includes, drop-ins and runtime defaults; this check sees what is actually applied.
A mapping is a cross-reference to where each standard places this requirement, anchored and cross-validated, not a claim of equivalence. A passing check is evidence toward these references, how to read it.
Why this rule matters
The Prefix Information Option in a Router Advertisement tells the host which IPv6 prefixes are on-link and usable for SLAAC autoconfiguration. Because RAs are unauthenticated, a rogue node can advertise forged prefixes to make the host self-assign attacker-controlled addresses or treat hostile prefixes as on-link, enabling man-in-the-middle and traffic redirection. A host with static addressing has no need to learn prefixes from the network.
What Pavois checks
Pavois reads the effective runtime value via the kernel_parameter resource (equivalent to sysctl net.ipv6.conf.all.accept_ra_pinfo) and asserts it is 0. The live kernel value is authoritative: a value in /etc/sysctl.d/* may be shadowed by a later drop-in or never applied, so reading the running parameter avoids the false pass that file inspection (OVAL/oscap) can give.
describe kernel_parameter('net.ipv6.conf.all.accept_ra_pinfo') do
its('value') { should cmp 0 }
end
describe command("grep -hsE '^[[:space:]]*net.ipv6.conf.all.accept_ra_pinfo[[:space:]]*=[[:space:]]*0([[:space:]]|$)' /etc/sysctl.conf /etc/sysctl.d/*.conf /run/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /lib/sysctl.d/*.conf 2>/dev/null") do
its('stdout') { should match(/\S/) }
endHow to verify it is applied
Run sysctl net.ipv6.conf.all.accept_ra_pinfo (or cat /proc/sys/net/ipv6/conf/all/accept_ra_pinfo). Expected output:
net.ipv6.conf.all.accept_ra_pinfo = 0
Inspect & investigate
No dedicated log exists. Check the live value with sysctl net.ipv6.conf.all.accept_ra_pinfo, audit where it was set with sysctl --system, and observe any prefixes the host configured via ip -6 addr show.
Remediation
Pavois's harden plan uses the sysctl resource to set net.ipv6.conf.all.accept_ra_pinfo to 0, persisting it in a Pavois-owned /etc/sysctl.d/ drop-in and applying it live (no reboot). Run it with pavois harden apply.
Pavois applies this with its own harden engine, the plan below, not a shell script:
| key | net.ipv6.conf.all.accept_ra_pinfo |
|---|---|
| resource | sysctl |
| value | 0 |
pavois harden plan localwhere the target is local, a user@host SSH alias, or a container , Docs
Impact & precautions
On hosts using SLAAC to obtain their IPv6 addresses, refusing prefix information stops automatic address configuration, which can break IPv6 connectivity. Apply only where the host uses static IPv6 or DHCPv6 with manual prefixes, the standard server case. Do not enforce on routers/gateways that must process RA prefix data. No effect on IPv4-only systems.
Standards mapping
| Standard | Reference | Type | Version | Confidence |
|---|---|---|---|---|
| ANSSI BP-028 | R13 | direct | 2.0 | high |
Each reference is a cross-reference anchored in the upstream benchmark and cross-validated against the SCAP Security Guide and ansible-lockdown, not a claim of equivalence. Direct = a prescriptive, line-level requirement; supporting = an abstract control family (NIST) the check provides evidence toward. How to read a mapping.