STIGUI
V-288819CAT II — Medium severitySV-288819r1261505_rule

Ubuntu 24.04 LTS must not assign an interactive login shell for system accounts.

Rule version UBTU-24-101100 · STIG v1 · 2026-09-09

Discussion

Ensuring shells are not given to system accounts upon login makes it more difficult for attackers to use system accounts.

Check

Verify Ubuntu 24.04 LTS system accounts do not have an interactive login shell with the following command:

Run the following command to list any system account (UID < 1000) that has an interactive shell, excluding authorized system utility accounts (root, sync, shutdown, halt):

$ awk -F: '(($3 > 0 && $3 < 1000) && $1 !~ /^(halt|sync|shutdown)$/ && $7 !~ /(nologin|false)$/) {print $1 ":" $3 ":" $7}' /etc/passwd

If the command returns any output, this is a finding.

Fix

Configure Ubuntu 24.04 LTS so that all noninteractive accounts on the system do not have an interactive shell assigned to them.

If the system account needs a shell assigned for mission operations, document the need with the information system security officer (ISSO).

Run the following command to disable the interactive shell for a specific noninteractive user account:

$ sudo usermod -s /usr/sbin/nologin <user>

Identifiers

Group ID
V-288819
Group title
SRG-OS-000445-GPOS-00199
Rule ID
SV-288819r1261505_rule
Check ID
C-93508r1261503_chk
Fix ID
F-93413r1261504_fix