8.1 Block system accounts, Ensure account 'daemon' is locked.

Information

Accounts that are not being used by regular users should be locked. Not only should the password field for the account be set to an invalid string (which is the default setting for these accounts under Solaris), but also the shell field in the password file should contain an invalid shell. /dev/null is a good choice because it is not a valid login shell, and should an attacker attempt to replace it with a copy of a valid shell the system will not operate properly.

See Also

https://workbench.cisecurity.org/files/633

Item Details

Audit Name: CIS Solaris 9 v1.3

Category: ACCESS CONTROL

References: 800-53|AC-3

Plugin: Unix

Control ID: 16a6517c968600752f96ef3cf2b09e11e3ea9416895608a4d81cf52b10b92ec5