Rule version OL08-00-010195 · STIG v2 · 2026-08-24
Ensuring shells are not given to system accounts upon login makes it more difficult for attackers to make use of system accounts.
Verify OL 8 system accounts do not have an interactive login shell.
Run the following command to list any system account (UID < 1000) that has an interactive shell, excluding authorized system utility accounts (root, sync, shutdown, halt):
$ awk -F: '(($3 > 0 && $3 < 1000) && $1 !~ /^(halt|sync|shutdown)$/ && $7 !~ /(nologin|false)$/) {print $1 ":" $3 ":" $7}' /etc/passwdIf the command returns any output, this is a finding.
If any system account (other than the root account) has a login shell and it is not documented with the information system security officer (ISSO), this is a finding.
Configure OL 8 so that all noninteractive accounts on the system do not have an interactive shell assigned to them.
If the system account needs a shell assigned for mission operations, document the need with the ISSO.
Run the following command to disable the interactive shell for a specific noninteractive user account:
$ sudo usermod --shell /usr/sbin/nologin <user>