Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

RHEL7 STIG: CCI-000016 The operating system must automatically remove or disable temporary user accounts after 72 hours. #70

Closed
shawndwells opened this issue Sep 6, 2014 · 5 comments · Fixed by #513
Assignees
Labels
RHEL Red Hat Enterprise Linux product related. RHEL7 Red Hat Enterprise Linux 7 product related. STIG STIG Benchmark related.

Comments

@shawndwells
Copy link
Member

CCI-000016 SRG-OS-000002 The operating system must automatically remove or disable temporary user accounts after 72 hours. "If temporary user accounts remain active when no longer needed or for an excessive period, these accounts may be used to gain unauthorized access. To mitigate this risk, automated termination of all temporary accounts must be set upon account creation.

Temporary accounts are established as part of normal account activation procedures when there is a need for short-term accounts without the demand for immediacy in account activation.

If temporary accounts are used, the operating system must be configured to automatically terminate these types of accounts after a DoD-defined time period of 72 hours.

To address access requirements, many operating systems may be integrated with enterprise level authentication/access mechanisms that meet or exceed access control policy requirements. "

@shawndwells shawndwells added this to the Draft RHEL 7 STIG milestone Sep 6, 2014
@shawndwells
Copy link
Member Author

AC-2 (2)

@redhatrises
Copy link
Contributor

@shawndwells can this be closed with the merging of #349? Seems like this should have auto-closed with the merge, but I just wanted to make sure that it wasn't open for another reason.

@shawndwells
Copy link
Member Author

not yet. looks like the CCE has been reused in RHEL6/7:

$ grep -rin 26436-6 *
6/input/system/software/disk_partitioning.xml:101:<ident cce="26436-6"  stig="RHEL-06-000004" />
6/kickstart/usgcb-server-with-gui-ks.cfg:107:# CCE-26436-6: Ensure /var/log/audit Located On Separate Partition
7/input/system/accounts/restrictions/account_expiration.xml:105:<ident cce="26436-6" />

and likely the xccdf needs to be added to stig profile.

I'll do this now.

@shawndwells
Copy link
Member Author

(p.s. @redhatrises thank you so much for helping to clear out the tickets!)

@shawndwells shawndwells added 2 - Working RHEL Red Hat Enterprise Linux product related. and removed 0 - Backlog help-wanted This PR/Issue needs help to go forward. labels Apr 8, 2015
@shawndwells shawndwells self-assigned this Apr 8, 2015
@shawndwells
Copy link
Member Author

@redhatrises updated and submitted PR for your review

@mpreisler mpreisler modified the milestone: Draft RHEL 7 STIG Jul 25, 2016
brett060102 added a commit to brett060102/content that referenced this issue Apr 2, 2021
@marcusburghardt marcusburghardt added RHEL7 Red Hat Enterprise Linux 7 product related. STIG STIG Benchmark related. labels Jun 23, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
RHEL Red Hat Enterprise Linux product related. RHEL7 Red Hat Enterprise Linux 7 product related. STIG STIG Benchmark related.
Projects
None yet
Development

Successfully merging a pull request may close this issue.

4 participants