Details
If the userlist file does not exist, then an unauthorized user may exist in the /etc/passwd file.
Solution
Create the /usr/aset/userlist file and populate it with a list of authorized users.
Supportive Information
The following resource is also helpful.
This security hardening control applies to the following category of controls within NIST 800-53: Access Control, Configuration Management.This control applies to the following type of system Unix.
References
- 800-53|AC-4(8)
- 800-53|CM-6b.
- CAT|II
- CCI|CCI-000032
- CCI|CCI-000366
- CSCv6|3.1
- Rule-ID|SV-226414r603265_rule
- STIG-ID|GEN000000-SOL00220
- STIG-Legacy|SV-955
- STIG-Legacy|V-955
- Vuln-ID|V-226414