Check: RHEL-07-020610
Red Hat Enterprise Linux 7 STIG:
RHEL-07-020610
(in versions v3 r14 through v1 r1)
Title
The Red Hat Enterprise Linux operating system must be configured so that all local interactive user accounts, upon creation, are assigned a home directory. (Cat II impact)
Discussion
If local interactive users are not assigned a valid home directory, there is no place for the storage and control of files they should own.
Check Content
Verify all local interactive users on the system are assigned a home directory upon creation. Check to see if the system is configured to create home directories for local interactive users with the following command: # grep -i create_home /etc/login.defs CREATE_HOME yes If the value for "CREATE_HOME" parameter is not set to "yes", the line is missing, or the line is commented out, this is a finding.
Fix Text
Configure the operating system to assign home directories to all new local interactive users by setting the "CREATE_HOME" parameter in "/etc/login.defs" to "yes" as follows. CREATE_HOME yes
Additional Identifiers
Rule ID: SV-204466r603261_rule
Vulnerability ID: V-204466
Group Title: SRG-OS-000480-GPOS-00227
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000366 |
The organization implements the security configuration settings. |
Controls
Number | Title |
---|---|
CM-6 |
Configuration Settings |