5.4.3 Ensure default group for the root account is GID 0

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

The usermod command can be used to specify which group the root user belongs to. This affects permissions of files that are created by the root user. Using GID 0 for the root account helps prevent root -owned files from accidentally becoming accessible to non-privileged users.

Solution

Run the following command to set the root user default group to GID 0: # usermod -g 0 root

See Also

https://benchmarks.cisecurity.org/tools2/linux/CIS_SUSE_Linux_Enterprise_11_Benchmark_v2.0.0.pdf

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-2

Plugin: Unix

Control ID: 8648daf6bd35261b2ea0688f0483c0c5ddf826b86f5af0cc51c66fd8ff8397c1