9.4 Restrict root Login to System Console

Information

The file /etc/securetty contains a list of valid terminals that may be logged in directly as root. Since the system console has special properties to handle emergency situations, it is important to ensure that the console is in a physically secure location and that unauthorized consoles have not been defined.

Solution

Remove entries for any consoles that are not in a physically secure location.

See Also

https://workbench.cisecurity.org/files/85

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-6(3)

Plugin: Unix

Control ID: 4dc0ad8e8ea0dd848de0b02a032e093c53f0c2a6899c7b97b4bea41c16273226