AlmaLinux OS 9 system accounts must not have an interactive login shell.
An XCCDF Rule
Description
Ensuring shells are not given to system accounts upon login makes it more difficult for attackers to make use of system accounts.
- ID
- SV-269300r1050182_rule
- Version
- ALMA-09-024990
- Severity
- Medium
- References
- Updated
Remediation Templates
A Manual Procedure
Configure AlmaLinux OS 9 so that all noninteractive accounts on the system do not have an interactive shell assigned to them.
If the system account needs a shell assigned for mission operations, document the need with the ISSO.
Run the following command to disable the interactive shell for a specific noninteractive user account, replacing <user> with the user that has a login shell.