13.20 Ensure shadow group is empty - No users with 'Shadow' as their Primary Group

Information

NOTE: Update SHADOW_GID with the appropriate value for the local environment.

Solution

Remove all users from the shadow group, and change the primary group of any users with shadow as their primary group.

See Also

https://workbench.cisecurity.org/files/91

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-2f.

Plugin: Unix

Control ID: e8b60357894189a08f92c78a65fc01ef1335bef39d4d0e4b7031d9f438a67919