SV-261371r996554_rule
V-261371
SRG-OS-000324-GPOS-00125
SLEM-05-431025
CAT II
10
Configure SLEM 5 to prevent nonprivileged users from executing privileged functions, including disabling, circumventing, or altering implemented security safeguards/countermeasures.
Use the following command to map a new user to the "sysadm_u" role:
> sudo semanage login -a -s sysadm_u <username>
Use the following command to map an existing user to the "sysadm_u" role:
> sudo semanage login -m -s sysadm_u <username>
Use the following command to map a new user to the "staff_u" role:
> sudo semanage login -a -s staff_u <username>
Use the following command to map an existing user to the "staff_u" role:
> sudo semanage login -m -s staff_u <username>
Use the following command to map a new user to the "user_u" role:
> sudo semanage login -a -s user_u <username>
Use the following command to map an existing user to the "user_u" role:
> sudo semanage login -m -s user_u <username>
Verify SLEM 5 prevents nonprivileged users from executing privileged functions, including disabling, circumventing, or altering implemented security safeguards/countermeasures.
Obtain a list of authorized users (other than system administrator and guest accounts) for the system.
Check the list against the system with the following command:
> sudo semanage login -l | more
Login Name SELinux User MLS/MCS Range Service
__default__ user_u s0-s0:c0.c1023 *
root unconfined_u s0-s0:c0.c1023 *
system_u system_u s0-s0:c0.c1023 *
joe staff_u s0-s0:c0.c1023 *
All administrators must be mapped to the "sysadm_u", "staff_u", or an appropriately tailored confined role as defined by the organization.
All authorized nonadministrative users must be mapped to the "user_u" role.
If any interactive users are not mapped in this way, this is a finding.
V-261371
False
SLEM-05-431025
Verify SLEM 5 prevents nonprivileged users from executing privileged functions, including disabling, circumventing, or altering implemented security safeguards/countermeasures.
Obtain a list of authorized users (other than system administrator and guest accounts) for the system.
Check the list against the system with the following command:
> sudo semanage login -l | more
Login Name SELinux User MLS/MCS Range Service
__default__ user_u s0-s0:c0.c1023 *
root unconfined_u s0-s0:c0.c1023 *
system_u system_u s0-s0:c0.c1023 *
joe staff_u s0-s0:c0.c1023 *
All administrators must be mapped to the "sysadm_u", "staff_u", or an appropriately tailored confined role as defined by the organization.
All authorized nonadministrative users must be mapped to the "user_u" role.
If any interactive users are not mapped in this way, this is a finding.
M
5596