7.1 Disable System Accounts - should pass if the default shell for 'nobody' is set to /usr/bin/false.

Information

There are a number of accounts provided with the Solaris OS that are used to manage applications and are not intended to provide an interactive shell.

Solution

Accounts that have been locked are prohibited from running commands on the system. Such accounts are not able to login to the system nor are they able to use scheduled execution facilities such as cron. To lock an account, use the command-
passwd -l [username]

See Also

https://workbench.cisecurity.org/files/614

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-6

Plugin: Unix

Control ID: a6ec849fe8b256537dbbc44ca91507426d5b0db9899d224ed1fd5759fff89226