Check: GEN000980
SUSE Linux Enterprise Server v11 for System z STIG:
GEN000980
(in versions v1 r12 through v1 r9)
Title
The system must prevent the root account from directly logging in except from the system console. (Cat II impact)
Discussion
Limiting the root account direct logins to only system consoles protects the root account from direct unauthorized access from a non-console device.
Check Content
Check /etc/securetty # more /etc/securetty If the file does not exist, or contains more than "console" or a single "tty" device this is a finding.
Fix Text
Create if needed and set the contents of /etc/securetty to a "console" or "tty" device. # echo console > /etc/securetty or # echo ttyS0 > /etc/securetty
Additional Identifiers
Rule ID: SV-44913r1_rule
Vulnerability ID: V-778
Group Title: GEN000980
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000770 |
The organization requires individuals to be authenticated with an individual authenticator when a group authenticator is employed. |
Controls
Number | Title |
---|---|
IA-2(5) |
Group Authentication |