Check: ANIX-00-001500
Anduril NixOS STIG:
ANIX-00-001500
(in version v1 r1)
Title
NixOS must require users to reauthenticate for privilege escalation. (Cat II impact)
Discussion
Without reauthentication, users may access resources or perform tasks for which they do not have authorization. When operating systems provide the capability to escalate a functional capability, it is critical the user reauthenticate.
Check Content
Verify NixOS enforces reauthentication with sudo with the following command: $ sudo grep timestamp_timeout /etc/sudoers Defaults timestamp_timeout=0 If "timestamp_timeout" is greater than 0, is commented out, or is missing, this is a finding.
Fix Text
Configure /etc/nixos/configuration.nix to enforce reauthentication with sudo by adding the following configuration settings: security.sudo.extraConfig = '' Defaults timestamp_timeout=0 ''; Rebuild the system with the following command: $ sudo nixos-rebuild switch
Additional Identifiers
Rule ID: SV-268155r1039536_rule
Vulnerability ID: V-268155
Group Title: SRG-OS-000480-GPOS-00227
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000366 |
Implement the security configuration settings. |
Controls
Number | Title |
---|---|
CM-6 |
Configuration Settings |