SV-208890r603263_rule
V-208890
SRG-OS-000241
OL6-00-000177
CAT III
10
Add the following to "/etc/audit/audit.rules", in order to capture events that modify account changes:
# audit_account_changes
-w /etc/group -p wa -k audit_account_changes
-w /etc/passwd -p wa -k audit_account_changes
-w /etc/gshadow -p wa -k audit_account_changes
-w /etc/shadow -p wa -k audit_account_changes
-w /etc/security/opasswd -p wa -k audit_account_changes
To determine if the system is configured to audit account changes, run the following command:
$sudo egrep -w '(/etc/passwd|/etc/shadow|/etc/group|/etc/gshadow|/etc/security/opasswd)' /etc/audit/audit.rules
If the system is configured to watch for account changes, lines should be returned for each file specified (and with "-p wa" for each).
If the system is not configured to audit account changes, this is a finding.
V-208890
False
OL6-00-000177
To determine if the system is configured to audit account changes, run the following command:
$sudo egrep -w '(/etc/passwd|/etc/shadow|/etc/group|/etc/gshadow|/etc/security/opasswd)' /etc/audit/audit.rules
If the system is configured to watch for account changes, lines should be returned for each file specified (and with "-p wa" for each).
If the system is not configured to audit account changes, this is a finding.
M
2928