GEN001460 - All interactive user home directories defined in the /etc/passwd file must exist.

Information

If a user has a home directory defined that does not exist, the user may be given the / directory, by default, as the current working directory upon logon. This could create a Denial of Service because the user would not be able to perform useful tasks in this location.

Solution

If a user has no home directory, determine why. If possible, delete accounts without a home directory. If the account is valid, then create the home directory using the appropriate system administration utility or manually.

For instance: mkdir directoryname; copy the skeleton files into the directory; chown accountname for the new directory and the skeleton files. Document all changes.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Oracle_Linux_5_V2R1_STIG.zip

Item Details

Category: ACCESS CONTROL, CONFIGURATION MANAGEMENT

References: 800-53|AC-6, 800-53|CM-6b., CAT|III, CCI|CCI-000225, CCI|CCI-000366, Rule-ID|SV-218305r603259_rule, STIG-ID|GEN001460, STIG-Legacy|SV-64579, STIG-Legacy|V-900, Vuln-ID|V-218305

Plugin: Unix

Control ID: a49ae40fd2bab811dfd04634c96b90d50a579a9cbbbf0bdb7f067e4fabe9ee54