Check: SLES-12-010710
SLES 12 STIG:
SLES-12-010710
(in versions v2 r13 through v2 r3)
Title
All SUSE operating system local interactive users must have a home directory assigned in the /etc/passwd file. (Cat II impact)
Discussion
If local interactive users are not assigned a valid home directory, there is no place for the storage and control of files they should own.
Check Content
Verify SUSE operating system local interactive users on the system have a home directory assigned. Check for missing local interactive user home directories with the following command: > sudo pwck -r user 'smithj': directory '/home/smithj' does not exist Ask the System Administrator (SA) if any users found without home directories are local interactive users. If the SA is unable to provide a response, check for users with a User Identifier (UID) of 1000 or greater with the following command: > sudo awk -F: '($3>=1000)&&($7 !~ /nologin/){print $1, $3, $6}' /etc/passwd If any interactive users do not have a home directory assigned, this is a finding.
Fix Text
Assign home directories to all SUSE operating system local interactive users that currently do not have a home directory assigned. Assign a home directory to users via the usermod command: > sudo usermod -d /home/smithj smithj
Additional Identifiers
Rule ID: SV-217170r646728_rule
Vulnerability ID: V-217170
Group Title: SRG-OS-000480-GPOS-00227
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000366 |
The organization implements the security configuration settings. |
Controls
Number | Title |
---|---|
CM-6 |
Configuration Settings |