-
Notifications
You must be signed in to change notification settings - Fork 25
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
5.6 | Ensure access to the su command is restricted
tasks do not account for lines commented out in pam.d
#25
Comments
FYI here is an example from the GSA how they handle this criteria in their role using
|
Signed-off-by: George Nalen <[email protected]>
Hello, George |
Signed-off-by: George Nalen <[email protected]>
The tasks for this CIS criteria first grep the
/etc/pam.d/su
file, and do not take into account a line that may be commented out, so the tasks get skipped ie.# auth required pam_wheel.so
Seems an update is needed to check if the line is commented out and uncomment it so that the control is applied properly.
The text was updated successfully, but these errors were encountered: