SOL-11.1-040230 - The operating system must require individuals to be authenticated with an individual authenticator prior to using a group authenticator.

Information

Allowing any user to elevate their privileges can allow them excessive control of the system tools.

Solution

The root role is required.

Convert the root user into a role.

# usermod -K type=role root

Add the root role to authorized users' logins.

# usermod -R +root [username]

Remove the root role from users who should not be authorized to assume it.

# usermod -R -root [username]

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_SOL_11_SPARC_V3R3_STIG.zip

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-2(5), CAT|II, CCI|CCI-000770, CCI|CCI-004045, Rule-ID|SV-216340r1016277_rule, STIG-ID|SOL-11.1-040230, STIG-Legacy|SV-60929, STIG-Legacy|V-48057, Vuln-ID|V-216340

Plugin: Unix

Control ID: b09a7d38ce9997e6cf633167ab0b6bb656198fdc346f6da1281acc8cb62361d1