2.2 Give the BIND User Account an Invalid Shell

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

The BIND user account, named by default, must not be used as a regular login account, and should be assigned an invalid or nologin shell to ensure that the account cannot be used to login.

Rationale:

Service accounts such as the named account represent a risk if they can be used to get a login shell to the system.

Solution

Change the named account to use the nologin shell as shown:

# chsh -s /sbin/nologin named

Default Value:

/sbin/nologin

See Also

https://benchmarks.cisecurity.org/downloads/show-single/?file=bind.300

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-3

Plugin: Unix

Control ID: 534d639ca49bcb48a006c4346188ef9665f9241a7afd81a479eb85fe626a3516