9.4 Ensure Password Fields are Not Empty

Information

An account with an empty password field means that anybody may log in as that user
without providing a password at all (assuming that the value PASSREQ=NO is set in
/etc/default/login).

All accounts must have passwords, be configured as 'Non-login,' or be locked.

Solution

Use the passwd -l command to lock accounts that are not permitted to execute commands
. Use the passwd -N command to set accounts to be non-login.

See Also

https://workbench.cisecurity.org/files/616

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-5(1)(a)

Plugin: Unix

Control ID: 67867bc32c91988f5fd07886d6c60657db88dd983535d797a42b89ec6b872a27