SV-216109r603268_rule
V-216109
SRG-OS-000003
SOL-11.1-040280
CAT II
10
The root role is required.
Perform the following to implement the recommended state:
# useradd -D -f 35
To set this policy on a user account, use the command(s):
# usermod -f 35 [username]
To set this policy on a role account, use the command(s):
# rolemod -f 35 [name]
Determine whether the 35-day inactivity lock is configured properly.
# useradd -D | xargs -n 1 | grep inactive |\
awk -F= '{ print $2 }'
If the command returns a result other than 35, this is a finding.
The root role is required for the "logins" command.
For each configured user name and role name on the system, determine whether a 35-day inactivity period is configured. Replace [username] with an actual user name or role name.
# logins -axo -l [username] | awk -F: '{ print $13 }'
If these commands provide output other than 35, this is a finding.
V-216109
False
SOL-11.1-040280
Determine whether the 35-day inactivity lock is configured properly.
# useradd -D | xargs -n 1 | grep inactive |\
awk -F= '{ print $2 }'
If the command returns a result other than 35, this is a finding.
The root role is required for the "logins" command.
For each configured user name and role name on the system, determine whether a 35-day inactivity period is configured. Replace [username] with an actual user name or role name.
# logins -axo -l [username] | awk -F: '{ print $13 }'
If these commands provide output other than 35, this is a finding.
M
4021