Check: RHEL-09-411030
RHEL 9 STIG:
RHEL-09-411030
(in versions v2 r3 through v1 r1)
Title
RHEL 9 duplicate User IDs (UIDs) must not exist for interactive users. (Cat II impact)
Discussion
To ensure accountability and prevent unauthenticated access, interactive users must be identified and authenticated to prevent potential misuse and compromise of the system. Satisfies: SRG-OS-000104-GPOS-00051, SRG-OS-000121-GPOS-00062, SRG-OS-000042-GPOS-00020
Check Content
Verify that RHEL 9 contains no duplicate UIDs for interactive users with the following command: $ sudo awk -F ":" 'list[$3]++{print $1, $3}' /etc/passwd If output is produced and the accounts listed are interactive user accounts, this is a finding.
Fix Text
Edit the file "/etc/passwd" and provide each interactive user account that has a duplicate UID with a unique UID.
Additional Identifiers
Rule ID: SV-258045r958482_rule
Vulnerability ID: V-258045
Group Title: SRG-OS-000104-GPOS-00051
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000135 |
Generate audit records containing the organization-defined additional information that is to be included in the audit records. |
CCI-000764 |
Uniquely identify and authenticate organizational users and associate that unique identification with processes acting on behalf of those users. |
CCI-000804 |
Uniquely identify and authenticate non-organizational users or processes acting on behalf of non-organizational users. |