4.5.3 Ensure default group for the root account is GID 0

Information

The usermod command can be used to specify which group the root user belongs to. This affects permissions of files that are created by the root user.

Using GID 0 for the root account helps prevent root -owned files from accidentally becoming accessible to non-privileged users.

Solution

Run the following command to set the root user default group to GID 0 :

# usermod -g 0 root

See Also

https://workbench.cisecurity.org/benchmarks/13775

Item Details

Category: ACCESS CONTROL, MEDIA PROTECTION

References: 800-53|AC-3, 800-53|AC-5, 800-53|AC-6, 800-53|MP-2, CSCv7|14.6

Plugin: Unix

Control ID: 9c9d73a0c5af9a0f42f193837eb65e19121bc272aa76420da8634fb1296b1b11