Check: GEN000000-LNX00600
SUSE Linux Enterprise Server v11 for System z STIG:
GEN000000-LNX00600
(in versions v1 r12 through v1 r9)
Title
The Linux PAM system must not grant sole access to admin privileges to the first user who logs into the console. (Cat II impact)
Discussion
If an unauthorized user has been granted privileged access while logged in at the console, the security posture of a system could be greatly compromised. Additionally, such a situation could deny legitimate root access from another terminal.
Check Content
Ensure the pam_console.so module is not configured in any files in /etc/pam.d by: # cd /etc/pam.d # grep pam_console.so * Or # ls –la /etc/security/console.perms If either the pam_console.so entry or the file /etc/security/console.perms is found then this is a finding.
Fix Text
Ensure PAM is not configured to grant sole access of administrative privileges to the first user logged in at the console. Remove the console.perms file if it exists: # rm /etc/security/console.perms
Additional Identifiers
Rule ID: SV-44665r1_rule
Vulnerability ID: V-4346
Group Title: GEN000000-LNX00600
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000225 |
The organization employs the concept of least privilege, allowing only authorized accesses for users (and processes acting on behalf of users) which are necessary to accomplish assigned tasks in accordance with organizational missions and business functions. |
CCI-000366 |
The organization implements the security configuration settings. |