GEN000760 - Accounts must be locked upon 35 days of inactivity.

Information

NOTE: Nessus has not performed this query, and this check is only provided for informational purposes.

Solution

All inactive accounts will have /sbin/nologin (or an equivalent), as the default shell in the /etc/passwd file and have the password disabled. Examine the user accounts using the 'last' command. Note the date of last login for each account. If any (other than system and application accounts) exceed 35 days or the maximum number of days set by the site, not to exceed 35 days, then disable the accounts using system-config-users tool. Alternately place a shell field of /sbin/nologin /bin/false or /dev/null in the passwd file entry for the account.

See Also

http://iasecontent.disa.mil/stigs/zip/U_RedHat_5_V1R17_STIG.zip

Item Details

References: CAT|II, CCI|CCI-000017, Group-ID|V-918, Rule-ID|SV-37314r2_rule, STIG-ID|GEN000760

Plugin: Unix

Control ID: ffcc95ba0b5b4a36c1c44b0cc054e422475ddb5466fb9f438a7f171536b63ca9