GSA / GSA/ansible-https-proxy

Lock the NGINX User Account

Abierto
#15 0 comentarios 0 reacciones 0 asignados Ver en GitHub
Lenguaje dominante
Sin datos de lenguaje
Estrellas
10
Forks
5
Métricas de merge de PR
Sin PR fusionados en 30 d

Descripción

>Draft CIS Benchmark 1.1.3 (**Level 2 Control**)

## Description
The user account under which NGINX runs should not have a valid password, but should be locked.

## Rationale
As a defense-in-depth measure the NGINX user account should be locked to prevent logins, and to prevent a user from su-ing to `nginx `using the password. In general there shouldn't be a need for anyone to have to `su `as `nginx`, and when there is a need, then `sudo `should be used instead, which would not require the `nginx `account password.

## Remediation
Use the `passwd `command to lock the `nginx `account: ``` # passwd -l nginx ```

## Audit
Ensure the `nginx `account is locked using the following: ``` # passwd -S nginx ``` The results will be similar to the following: ``` nginx LK 2016-06-23 0 99999 7 -1 (Password locked.) ``` or ``` nginx L 06/23/2016 -1 -1 -1 -1 ```

Guía de contribución

Abrir la guía de contribución

Evaluación

Este issue todavía no se ha evaluado.

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.