Check: RHEL-09-411110
RHEL 9 STIG:
RHEL-09-411110
(in versions v1 r3 through v1 r1)
Title
RHEL 9 groups must have unique Group ID (GID). (Cat II impact)
Discussion
To ensure accountability and prevent unauthenticated access, groups must be identified uniquely to prevent potential misuse and compromise of the system.
Check Content
Verify that RHEL 9 contains no duplicate GIDs for interactive users with the following command: $ cut -d : -f 3 /etc/group | uniq -d If the system has duplicate GIDs, this is a finding.
Fix Text
Edit the file "/etc/group" and provide each group that has a duplicate GID with a unique GID.
Additional Identifiers
Rule ID: SV-258061r926170_rule
Vulnerability ID: V-258061
Group Title: SRG-OS-000104-GPOS-00051
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000764 |
The information system uniquely identifies and authenticates organizational users (or processes acting on behalf of organizational users). |
Controls
Number | Title |
---|---|
IA-2 |
Identification And Authentication (Organizational Users) |