STIGQter STIGQter: STIG Summary: Red Hat Enterprise Linux 10 Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 01 Jul 2026:

RHEL 10 must restrict the use of the "su" command.

DISA Rule

SV-281205r1166567_rule

Vulnerability Number

V-281205

Group Title

SRG-OS-000373-GPOS-00156

Rule Version

RHEL-10-600500

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure RHEL 10 to require users to be in the "wheel" group to run the "su" command.

Edit the configuration file:

$ sudo vi /etc/pam.d/su

Add the following lines:

auth required pam_wheel.so use_uid
$ sed '/^[[:space:]]*#[[:space:]]*auth[[:space:]]\+required[[:space:]]\+pam_wheel\.so[[:space:]]\+use_uid$/s/^[[:space:]]*#//' -i /etc/pam.d/su

If necessary, create a "wheel" group and add administrative users to the group.

Check Contents

Verify RHEL 10 requires users to be members of the "wheel" group to run "su".

Verify the configuration with the following command:

$ sudo grep pam_wheel /etc/pam.d/su
auth required pam_wheel.so use_uid

If a line for "pam_wheel.so" does not exist or is commented out, this is a finding.

Vulnerability Number

V-281205

Documentable

False

Rule Version

RHEL-10-600500

Severity Override Guidance

Verify RHEL 10 requires users to be members of the "wheel" group to run "su".

Verify the configuration with the following command:

$ sudo grep pam_wheel /etc/pam.d/su
auth required pam_wheel.so use_uid

If a line for "pam_wheel.so" does not exist or is commented out, this is a finding.

Check Content Reference

M

Target Key

5733