SV-100343r1_rule
V-89693
SRG-OS-000109-GPOS-00056
VRAU-SL-000705
CAT I
10
Configure the SLES for vRealize to prevent direct logons to the "root" account by performing the following operations:
Add this line to the /etc/group file:
admin:x:[UNIQUE_NUMBER]:[USERNAME]
USERNAME is the user to be added to the admin group.
UNIQUE_NUMBER is a number entered into the ID field of an entry that is unique to all other IDs in the file.
Comment out the following lines in /etc/sudoers file:
Default targetpw
ALL ALL=(ALL) ALL
Under the line in the /etc/sudoers file:
root ALL=(ALL) All
Add the following line:
%admin ALL=(ALL) ALL
Run the following command:
# passwd -d root
Verify the SLES for vRealize prevents direct logons to the "root" account by running the following command:
# grep root /etc/shadow | cut -d "":"" -f 2
If the returned message contains any text, this is a finding.
V-89693
False
VRAU-SL-000705
Verify the SLES for vRealize prevents direct logons to the "root" account by running the following command:
# grep root /etc/shadow | cut -d "":"" -f 2
If the returned message contains any text, this is a finding.
M
3459