Check: RHEL-09-411110
RHEL 9 STIG:
RHEL-09-411110
(in versions v2 r3 through v1 r1)
Title
RHEL 9 groups must have unique Group ID (GID). (Cat II impact)
Discussion
To ensure accountability and prevent unauthenticated access, groups must be identified uniquely to prevent potential misuse and compromise of the system.
Check Content
Verify that RHEL 9 contains no duplicate GIDs for interactive users with the following command: $ cut -d : -f 3 /etc/group | uniq -d If the system has duplicate GIDs, this is a finding.
Fix Text
Edit the file "/etc/group" and provide each group that has a duplicate GID with a unique GID.
Additional Identifiers
Rule ID: SV-258061r958482_rule
Vulnerability ID: V-258061
Group Title: SRG-OS-000104-GPOS-00051
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000764 |
Uniquely identify and authenticate organizational users and associate that unique identification with processes acting on behalf of those users. |
Controls
Number | Title |
---|---|
IA-2 |
Identification and Authentication (organizational Users) |