SV-269778r1051719_rule
V-269778
SRG-APP-000148-NDM-000346
OS10-NDM-000360
CAT II
10
Configure the OS10 Switch to only allow one local account for use as the account of last resort.
Disable the linuxadmin system user:
OS10(config)# system-user linuxadmin disable
%Warning : Operation is not recommended in absence of console access.
Do you want to proceed ? [yes/no(default)]:yes
OS10(config)#
Delete any extra local users with the following command:
OS10(config)# no username admin
Note: The account of last resort must be added before the default admin account can be deleted.
Review the network device configuration to determine if an account of last resort is configured. Verify default admin and other vendor-provided accounts are disabled, removed, or renamed where possible. Verify the username and password for the account of last resort is contained within a sealed envelope and kept in a safe.
Step 1: Verify the Dell OS10 Switch is configured with only a single local user account. If one local account does not exist for use as the account of last resort, this is a finding.
Verify the role is sysadmin.
OS10# show running-configuration users
username alradmin password **** role sysadmin priv-lvl 15
OS10#
Step 2: Verify the linuxadmin system user has been disabled:
OS10# show running-configuration | grep system-user
system-user linuxadmin disable
system-user linuxadmin password ****
OS10#
If one local account does not exist for use as the account of last resort or the linuxadmin system-user has not been disabled, this is a finding.
V-269778
False
OS10-NDM-000360
Review the network device configuration to determine if an account of last resort is configured. Verify default admin and other vendor-provided accounts are disabled, removed, or renamed where possible. Verify the username and password for the account of last resort is contained within a sealed envelope and kept in a safe.
Step 1: Verify the Dell OS10 Switch is configured with only a single local user account. If one local account does not exist for use as the account of last resort, this is a finding.
Verify the role is sysadmin.
OS10# show running-configuration users
username alradmin password **** role sysadmin priv-lvl 15
OS10#
Step 2: Verify the linuxadmin system user has been disabled:
OS10# show running-configuration | grep system-user
system-user linuxadmin disable
system-user linuxadmin password ****
OS10#
If one local account does not exist for use as the account of last resort or the linuxadmin system-user has not been disabled, this is a finding.
M
5666