9.2.16 Check That Reserved UIDs Are Assigned to System Accounts

Information

Traditionally, UNIX systems establish 'reserved' UIDs (0-499 range) that are intended for system accounts.

Rationale:

If a user is assigned a UID that is in the reserved range, even if it is not presently in use, security exposures can arise if a subsequently installed application uses the same UID.

Solution

If it's determined that these accounts should not be within the reserved UID range, change the UIDs that are in the reserved range to one that is in the user range. Review all files owned by the reserved UID to determine which UID they are supposed to belong to.

Default Value:

OS Default: N/A

See Also

https://workbench.cisecurity.org/files/3096

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, CSCv7|5.1

Plugin: Unix

Control ID: 2bcd1557883439f3e2ee0a0f348d42c8b9919fce8f1313cbaeb5df3e8340890a