SOL-11.1-040430 - Logins to the root account must be restricted to the system console only.

Information

Use an authorized mechanism such as RBAC and the "su" command to provide administrative access to unprivileged accounts. These mechanisms provide an audit trail in the event of problems.

Solution

The root role is required.

Modify the /etc/default/login file

# pfedit /etc/default/login

Locate the line containing:

CONSOLE

Change it to read:

CONSOLE=/dev/console

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_SOL_11_SPARC_V3R6_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|II, CCI|CCI-000366, Rule-ID|SV-216361r959010_rule, STIG-ID|SOL-11.1-040430, STIG-Legacy|SV-60999, STIG-Legacy|V-48127, Vuln-ID|V-216361

Plugin: Unix

Control ID: 75e37c694217aebf1bcfed518d98563e0954e4f52cc36b002f4ff155ec509bac