SV-279539r1192552_rule
V-279539
SRG-OS-000002-GPOS-00002
NXAC-OS-000016
CAT II
10
If a temporary account must be created, configure the system to terminate the account after a 72-hour time period using the following command.
sudo chage -E `date -d "+3 days" +%Y-%m-%d` system_account_name
Verify temporary accounts have been provisioned with an expiration date of 72 hours.
1. For every existing temporary account, run the following command to obtain its account expiration information:
$ sudo chage -l system_account_name
2. Verify each account has an expiration date set within 72 hours.
If any temporary accounts have no expiration date set or do not expire within 72 hours, this is a finding.
V-279539
False
NXAC-OS-000016
Verify temporary accounts have been provisioned with an expiration date of 72 hours.
1. For every existing temporary account, run the following command to obtain its account expiration information:
$ sudo chage -l system_account_name
2. Verify each account has an expiration date set within 72 hours.
If any temporary accounts have no expiration date set or do not expire within 72 hours, this is a finding.
M
5730