AZLX-23-002485 - Amazon Linux 2023 must ensure all interactive users have unique User IDs (UIDs).

Information

To ensure accountability and prevent unauthenticated access, interactive users must be identified and authenticated to prevent potential misuse and compromise of the system.

Satisfies: SRG-OS-000104-GPOS-00051, SRG-OS-000121-GPOS-00062, SRG-OS-000042-GPOS-00020

Solution

Configure Amazon Linux 2023 to contain no duplicate UIDs for interactive users.

Edit the file "/etc/passwd" and provide each interactive user account that has a duplicate UID with a unique UID.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Amazon_Linux_2023_V1R1_STIG.zip

Item Details

Category: AUDIT AND ACCOUNTABILITY, IDENTIFICATION AND AUTHENTICATION

References: 800-53|AU-3(1), 800-53|IA-2, 800-53|IA-8, CAT|II, CCI|CCI-000135, CCI|CCI-000764, CCI|CCI-000804, Rule-ID|SV-274160r1120663_rule, STIG-ID|AZLX-23-002485, Vuln-ID|V-274160

Plugin: Unix

Control ID: 759d488cb6fffc4cde5ee181173f73e72ca50ce4c5cbde4149baf4bf111aa892