GEN000850 - The system must restrict the ability to switch to the root user to members of a defined group - roles=root

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Configuring a supplemental group for users permitted to switch to the root user prevents unauthorized users from accessing the root account, even with knowledge of the root credentials.

Solution

Convert the root user into a role.
# usermod -K type=role root

Add the root role to authorized users' logins.
# usermod -R root <userid>

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_SOL_10_x86_V2R2_STIG.zip

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-6(10), CAT|III, CCI|CCI-000770, Rule-ID|SV-227596r603266_rule, STIG-ID|GEN000850, STIG-Legacy|SV-39876, STIG-Legacy|V-22308, Vuln-ID|V-227596

Plugin: Unix

Control ID: 2d786814f56a2e62f8f6a2276e65fa18530862f92b6d4da610d22cfbaae71366