SV-216361r603267_rule
V-216361
SRG-OS-000480
SOL-11.1-040430
CAT II
10
The root role is required.
Modify the /etc/default/login file
# pfedit /etc/default/login
Locate the line containing:
CONSOLE
Change it to read:
CONSOLE=/dev/console
This check applies to the global zone only. Determine the zone that you are currently securing.
# zonename
If the command output is "global", this check applies.
Determine if root login is restricted to the console.
# grep "^CONSOLE=/dev/console" /etc/default/login
If the output of this command is not:
CONSOLE=/dev/console
this is a finding.
V-216361
False
SOL-11.1-040430
This check applies to the global zone only. Determine the zone that you are currently securing.
# zonename
If the command output is "global", this check applies.
Determine if root login is restricted to the console.
# grep "^CONSOLE=/dev/console" /etc/default/login
If the output of this command is not:
CONSOLE=/dev/console
this is a finding.
M
4022