9.16 Check for Duplicate GIDs

Information

Although the groupadd program will not let you create a duplicate Group ID (GID), it is possible for an administrator to manually edit the /etc/group file and change the GID field.

Solution

Based on the results of the script, establish unique GIDs and review all files owned by the shared GID to determine which group they are supposed to belong to.

See Also

https://workbench.cisecurity.org/files/614

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-4d.

Plugin: Unix

Control ID: b45ed80477514aa86bafd554f8820ef6c1bc8ad96e88acc299682877aa0744ce