4.8.1 Ensure herald is configured

Information

This change adds a default herald to /etc/security/login.cfg

This change puts into place a suggested login herald to replace the default entry. A herald should not provide any information about the operating system or version. Instead, it should detail a company standard acceptable use policy

This

suggestion

for a herald should be tailored to reflect your corporate standard policy.

Solution

Add a default login herald to /etc/security/login.cfg :

chsec -f /etc/security/login.cfg -s default -a herald="Unauthorized use of this system is prohibited.\nlogin:"

See Also

https://workbench.cisecurity.org/benchmarks/10385

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-8

Plugin: Unix

Control ID: b48a2b233bf19081038c21c810cf952ff60469a2bd1ce9efa6e60c2ee2ff3570