GEN002140 - All shells referenced in /etc/passwd must be listed in the /etc/shells file, except any shells specified for the purpose of preventing logins.

Information

The shells file lists approved default shells. It helps provide layered defense to the security approach by ensuring users cannot change their default shell to an unauthorized shell that may not be secure.

Solution

Use the chsh utility or edit the /etc/passwd file and correct the error by changing the default shell of the account in error to an acceptable shell name contained in the /etc/shells file.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_SOL_10_SPARC_V2R4_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|II, CCI|CCI-000366, Rule-ID|SV-226567r603265_rule, STIG-ID|GEN002140, STIG-Legacy|SV-917, STIG-Legacy|V-917, Vuln-ID|V-226567

Plugin: Unix

Control ID: 57fb2ea9b8346700e9e5479f0c9b1fb96de7211215ea495059fa55cb065cf405