1.78 SLES-15-020091

Information

The SUSE operating system must not have unnecessary account capabilities.

GROUP ID: V-234875
RULE ID: SV-234875r991589

Accounts providing no operational purpose provide additional opportunities for system compromise. Therefore all necessary non interactive accounts should not have an interactive shell assigned to them.

NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.

Solution

Configure the SUSE operating system so that all non-interactive accounts on the system have no interactive shell assigned to them.

Run the following command to disable the interactive shell for a specific non-interactive user account:

sudo usermod --shell /sbin/nologin nobody

See Also

https://workbench.cisecurity.org/benchmarks/23779