Check: GEN000850
SUSE Linux Enterprise Server v11 for System z STIG:
GEN000850
(in versions v1 r12 through v1 r9)
Title
The system must restrict the ability to switch to the root user to members of a defined group. (Cat III impact)
Discussion
Configuring a supplemental group for users permitted to switch to the root user prevents unauthorized users from accessing the root account, even with knowledge of the root credentials.
Check Content
Check that /etc/pam.d/su and /etc/pam.d/su-l use pam_wheel. # grep pam_wheel /etc/pam.d/su /etc/pam.d/su-l If pam_wheel is not present, or is commented out, this is a finding.
Fix Text
Edit /etc/pam.d/su and /etc/pam.d/su-l Uncomment or add a line such as "auth required pam_wheel.so". If necessary, create a "wheel" group and add administrative users to the group.
Additional Identifiers
Rule ID: SV-44899r1_rule
Vulnerability ID: V-22308
Group Title: GEN000850
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000009 |
The organization manages information system accounts by identifying authorized users of the information system and specifying access privileges. |
Controls
Number | Title |
---|---|
No controls are assigned to this check |