Give the NGINX User Account an Invalid Shell
- 主要语言
- 没有语言数据
- 星标
- 10
- 派生
- 5
- PR 合并指标
- 30 天内没有已合并 PR
描述
>Draft CIS Benchmark 1.1.2
## Description
The `nginx `account must not be used as a regular login account, and should be assigned an invalid or `nologin `shell to ensure that the account cannot be used to login.
## Rationale
Service accounts such as the `nginx `account represent a risk if they can be used to get a login shell to the system.
## Remediation
Change the `nginx `account to use the `nologin `shell or an invalid shell such as `/dev/null`: ``` # chsh -s /sbin/nologin nginx ```
## Audit
Check the `nginx `login shell in the `/etc/passwd` file: ``` # grep nginx /etc/passwd ``` The `nginx `account shell must be `/sbin/nologin` or `/dev/null `similar to the following: ``` nginx:x:483:479:nginx user:/var/cache/nginx:/sbin/nologin ```
贡献指南
评估
这个 Issue 还没有评估数据。