GEN000850 - The system must restrict the ability to switch to the root user to members of a defined group

Information

Configuring a supplemental group for users permitted to switch to the root user prevents unauthorized users from accessing the root account, even with knowledge of the root credentials.

Solution

Edit /etc/default/security and uncomment, set, or add the SU_ROOT_GROUP setting with a value of wheel or equivalent. If necessary, create a wheel group and add administrative users to the group.

See Also

https://iasecontent.disa.mil/stigs/zip/U_HPUX_11-31_V1R19_STIG.zip

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-6, CAT|III, CCI|CCI-000009, Rule-ID|SV-26349r1_rule, STIG-ID|GEN000850, Vuln-ID|V-22308

Plugin: Unix

Control ID: 7bff824b8b3560b5921e835da8574ef7c1354704e1480d3b442d1e7ae9ce65d1