4.7.1 Ensure herald is configured

Information

The contents of the herald are displayed to users prior to login for local terminals.

Warning messages inform users who are attempting to login to the system of their legal status regarding the system and should include the name of the organization that owns the system and any monitoring policies that are in place.

Displaying OS and patch level information in login banners is highly discouraged because this provides detailed system information to attackers attempting to target specific exploits of a system.

Authorized users can easily get this information once they have logged in.

Solution

Add a default login herald to /etc/security/login.cfg with the appropriate contents according to your site policy:

chsec -f /etc/security/login.cfg -s default -a herald="Authorized users only. All activity may be monitored and reported.\\nlogin: "

See Also

https://workbench.cisecurity.org/benchmarks/19066

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-8

Plugin: Unix

Control ID: e4107d6d029342102fdc926db8458289bb86f504c307630c627302b2eb189dce