GEN001460 - All interactive user home directories defined in the /etc/passwd file must exist.

Information

If a user has a home directory defined that does not exist, the user may be given the / directory, by default, as the current working directory upon logon. This could create a Denial of Service because the user would not be able to perform useful tasks in this location.

Solution

If a user has no home directory, determine why. If possible, delete accounts without a home directory. If the account is valid, then create the home directory using the appropriate system administration utility or manually.
For instance: mkdir directoryname; copy the skeleton files into the directory; chown accountname for the new directory and the skeleton files. Document all changes.

See Also

http://iasecontent.disa.mil/stigs/zip/U_RedHat_5_V1R18_STIG.zip

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-6, CAT|III, CCI|CCI-000225, Group-ID|V-900, Rule-ID|SV-37379r1_rule, STIG-ID|GEN001460, Vuln-ID|V-900

Plugin: Unix

Control ID: 2aa8b335997bedfc9b4098f28d671afc3c3a0b9779c13d10b9dbb0f6220cac7a