5.5.10 Ensure upon user creation a home directory is assigned.

Information

The operating system must be configured so that all local interactive user accounts, upon creation, are assigned a home directory.

If local interactive users are not assigned a valid home directory, there is no place for the storage and control of files they should own.

Solution

Configure the operating system to assign home directories to all new local interactive users by setting the CREATE_HOME parameter in /etc/login.defs to yes as follows.

Example: vim /etc/login.defs

Add, uncomment or update the following line:

CREATE_HOME yes

See Also

https://workbench.cisecurity.org/benchmarks/8415

Item Details

Category: ACCESS CONTROL, MEDIA PROTECTION

References: 800-53|AC-3, 800-53|AC-5, 800-53|AC-6, 800-53|MP-2, CSCv7|14.6

Plugin: Unix

Control ID: d880683b75d84e078fa85d2431ec81224d76299ca7ff79207ae367f318c2ae43