Check: GEN000880
SOLARIS 9 SPARC STIG:
GEN000880
(in version v1 r12)
Title
The root account must be the only account having an UID of 0. (Cat II impact)
Discussion
If an account has an UID of 0, it has root authority. Multiple accounts with an UID of 0 afford more opportunity for potential intruders to guess a password for a privileged account.
Check Content
Fix Text
Remove or change the UID of accounts other than root that have UID 0.
Additional Identifiers
Rule ID: SV-39820r1_rule
Vulnerability ID: V-773
Group Title: GEN000880
Expert Comments
Expert comments are only available to logged-in users.
CCIs
CCIs tied to check.
Number | Definition |
---|---|
CCI-000366 |
Implement the security configuration settings. |
Controls
Controls tied to check. These are derived from the CCIs shown above.
Number | Title |
---|---|
CM-6 |
Configuration Settings |