SV-269384r1050267_rule
V-269384
SRG-OS-000118-GPOS-00060
ALMA-09-035660
CAT II
10
Configure AlmaLinux OS 9 to disable account identifiers after 35 days of inactivity after the password expiration.
Run the following command to change the configuration for useradd:
$ useradd -D -f 35
The recommendation is 35 days, but a lower value is acceptable.
Verify that AlmaLinux OS 9 account identifiers (individuals, groups, roles, and devices) are disabled after 35 days of inactivity with the following command:
$ useradd -D | grep INACTIVE
INACTIVE=35
If the value of "INACTIVE" is set to "-1", a value greater than "35", or is missing, this is a finding.
V-269384
False
ALMA-09-035660
Verify that AlmaLinux OS 9 account identifiers (individuals, groups, roles, and devices) are disabled after 35 days of inactivity with the following command:
$ useradd -D | grep INACTIVE
INACTIVE=35
If the value of "INACTIVE" is set to "-1", a value greater than "35", or is missing, this is a finding.
M
5664