In the event the authentication server is unavailable, there must be one local account of last resort.
DISA Rule
SV-86153r1_rule
Vulnerability Number
V-71529
Group Title
SRG-APP-000148-NDM-000346
Rule Version
CAGW-DM-000150
Severity
CAT II
CCI(s)
- CCI-001358 - The organization establishes privileged user accounts in accordance with a role-based access scheme that organizes allowed information system access and privileges into roles.
- CCI-002111 - The organization identifies and selects the organization-defined information system account types of information system accounts which support organizational missions/business functions.
Weight
10
Fix Recommendation
Configure the "root" account as the local account of last resort.
Disable the "ssgconfig" account by destroying its password and making the login shell "/sbin/nologin".
Check Contents
Verify the "root" (or its equivalent, renamed account) is listed in the password configuration files.
If the "root" account is not listed in the password configuration files, this is a finding.
Vulnerability Number
V-71529
Documentable
False
Rule Version
CAGW-DM-000150
Severity Override Guidance
Verify the "root" (or its equivalent, renamed account) is listed in the password configuration files.
If the "root" account is not listed in the password configuration files, this is a finding.
Check Content Reference
M
Target Key
3051
Comments