5.4.2.2 Ensure root is the only GID 0 account

Information

The usermod command can be used to specify which group the root account belongs to. This affects permissions of files that are created by the root account.

Using GID 0 for the root account helps prevent root -owned files from accidentally becoming accessible to non-privileged users.

Solution

Run the following command to set the root user's GID to 0 :

# usermod -g 0 root

Run the following command to set the root group's GID to 0 :

# groupmod -g 0 root

Remove any users other than the root user with GID 0 or assign them a new GID if appropriate.

See Also

https://workbench.cisecurity.org/benchmarks/18211

Item Details

Category: ACCESS CONTROL, MEDIA PROTECTION

References: 800-53|AC-3, 800-53|AC-5, 800-53|AC-6, 800-53|MP-2, CSCv7|14.6

Plugin: Unix

Control ID: 2eaf1382f740fc520e8bbd58fc368af9e231b707e19d987086f49bf8fbf82cb9