SV-99225r1_rule
V-88575
SRG-OS-000109-GPOS-00056
VROM-SL-000685
CAT I
10
Configure SLES for vRealize to prevent direct logins to the root account by performing the following operations:
Add this line to the "/etc/group" file:
admin:x:[UNIQUE_NUMBER]:[USERNAME]
USERNAME is the user you wish to add to the admin group.
UNIQUE_NUMBER is a number entered into the ID field of an entry that is unique to all other IDs in the file.
Comment out the following lines in "/etc/sudoers" file:
Default targetpw
ALL ALL=(ALL) ALL
Under the line in the "/etc/sudoers" file:
root ALL=(ALL) All
Add the following line:
%admin ALL=(ALL) ALL
Run the following command:
# passwd -d root
Verify SLES for vRealize prevents direct logons to the root account by running the following command:
# grep root /etc/shadow | cut -d "":"" -f 2
If the returned message contains any text, this is a finding.
V-88575
False
VROM-SL-000685
Verify SLES for vRealize prevents direct logons to the root account by running the following command:
# grep root /etc/shadow | cut -d "":"" -f 2
If the returned message contains any text, this is a finding.
M
3461