SV-261372r1184420_rule
V-261372
SRG-OS-000480-GPOS-00227
SLEM-05-432010
CAT II
10
Configure the sudoers security policy to use the invoking user's password for privilege escalation.
Define the defaults in a configuration file in the /etc/sudoers.d/ directory with the following command and entries:
> sudo visudo -f /etc/sudoers.d/hardening_defaults
Defaults !targetpw
Defaults !rootpw
Defaults !runaspw
Verify that the sudoers security policy is configured to use the invoking user's password for privilege escalation with the following command:
> sudo egrep -ir '(rootpw|targetpw|runaspw)' /etc/sudoers /etc/sudoers.d* | grep -v '#'
/etc/sudoers.d/hardening_defaults:Defaults !targetpw
/etc/sudoers.d/hardening_defaults:Defaults !rootpw
/etc/sudoers.d/hardening_defaults:Defaults !runaspw
If "Defaults" types are not defined for "!targetpw", "!rootpw", and "!runaspw", there are conflicting results between files, this is a finding.
V-261372
False
SLEM-05-432010
Verify that the sudoers security policy is configured to use the invoking user's password for privilege escalation with the following command:
> sudo egrep -ir '(rootpw|targetpw|runaspw)' /etc/sudoers /etc/sudoers.d* | grep -v '#'
/etc/sudoers.d/hardening_defaults:Defaults !targetpw
/etc/sudoers.d/hardening_defaults:Defaults !rootpw
/etc/sudoers.d/hardening_defaults:Defaults !runaspw
If "Defaults" types are not defined for "!targetpw", "!rootpw", and "!runaspw", there are conflicting results between files, this is a finding.
M
5596