GEN000000-LNX001476 - The /etc/gshadow file must not contain any group password hashes.

Information

Group passwords are typically shared and should not be used.

Solution

Edit /etc/gshadow and change the password field to an exclamation point (!) to lock the group password.

See Also

http://iasecontent.disa.mil/stigs/zip/U_RedHat_5_V1R18_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|II, CCI|CCI-000366, Group-ID|V-22349, Rule-ID|SV-37386r1_rule, STIG-ID|GEN000000-LNX001476, Vuln-ID|V-22349

Plugin: Unix

Control ID: 2e43918c68d19fb8c2b02e31ef029f2c7c0dc7744daaf9bd77c8851325f82f38