# Cis Apache24 3.3

> Ensure the Apache User Account Is Locked

- Skill: `cyberstrikeus/cis-apache24-3-3` (Agent Skill)
- Install (CLI): `npx skillmds@latest add cyberstrikeus/cis-apache24-3-3`
- Raw SKILL.md: https://api.skillmd.com/api/skills/cyberstrikeus/cis-apache24-3-3/raw
- Safety review: PASS (external: skill-scanner PASS, skillspector PASS)
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: Coding & Dev Tools
- Author: cyberstrikeus (https://skillmd.com/u/cyberstrikeus)
- Updated: 2026-09-17
- Page: https://skillmd.com/skills/cyberstrikeus/cis-apache24-3-3

---


# 3.3 Ensure the Apache User Account Is Locked

## Profile Applicability

- Level 1

## Description

The user account under which Apache runs should not have a valid password, but should be locked.

## Rationale

As a defense-in-depth measure the Apache user account should be locked to prevent logins, and to prevent a user from su'ing to `apache` using the password. In general, there shouldn't be a need for anyone to have to su as `apache`, and when there is a need, then `sudo` should be used instead, which would not require the `apache` account password.

## Audit

Ensure the `apache` account is locked using the following:

```bash
# passwd -S apache
```

The results will be similar to the following:

```
apache LK 2010-01-28 0 99999 7 -1 (Password locked.)

- or -

apache L 07/02/2012 -1 -1 -1 -1
```

## Remediation

Use the `passwd` command to lock the `apache` account:

```bash
# passwd -l apache
```

## Default Value

The default user is `daemon` and the account is typically locked.

## CIS Controls

| Controls Version | Control                                                                                                                            | IG 1 | IG 2 | IG 3 |
| ---------------- | ---------------------------------------------------------------------------------------------------------------------------------- | ---- | ---- | ---- |
| v8               | 5.3 Disable Dormant Accounts<br>Delete or disable any dormant accounts after a period of 45 days of inactivity, where supported.   | ●    | ●    | ●    |
| v7               | 16.8 Disable Any Unassociated Accounts<br>Disable any account that cannot be associated with a business process or business owner. | ●    | ●    | ●    |

## Profile

- Level 1

