CIS Ubuntu 14.04 LTS - 5.5 Ensure root login is restricted to system console

Verify root login is restricted to physically secure system consoles via /etc/securetty

cyberstrikeus Updated

File contents

5.5 Ensure root login is restricted to system console (Not Scored)

Profile Applicability

  • Level 1 - Server
  • Level 1 - Workstation

Description

The file /etc/securetty contains a list of valid terminals that may be logged in directly as root.

Rationale

Since the system console has special properties to handle emergency situations, it is important to ensure that the console is in a physically secure location and that unauthorized consoles have not been defined.

Audit Procedure

cat /etc/securetty

Expected Result

Review the output and verify only physically secure consoles are listed.

Remediation

Remove entries for any consoles that are not in a physically secure location.

Default Value

Varies by installation.

References

  • CIS Controls: 5.1 - Minimize And Sparingly Use Administrative Privileges

Profile

  • Level 1 - Server
  • Level 1 - Workstation

cyberstrikeus/cyberstrike/tree/main/.cyberstrike/skill/CIS_benchmarks/Operating_Systems/Ubuntu/cis-ubuntu-linux-14-04-lts-benchmark-v2/cis-ubuntu1404-v210-5-5 commit 29e4621413

Frequently asked questions

npx skillmds@latest add cyberstrikeus/cis-ubuntu-14-04-lts-5-5-ensure-root-login-is-restricted-to-