STIGUI
V-288824CAT II — Medium severitySV-288824r1261628_rule

OL 8 system accounts must not have an interactive login shell.

Rule version OL08-00-010195 · STIG v2 · 2026-08-24

Discussion

Ensuring shells are not given to system accounts upon login makes it more difficult for attackers to make use of system accounts.

Check

Verify OL 8 system accounts do not have an interactive login shell.

Run the following command to list any system account (UID < 1000) that has an interactive shell, excluding authorized system utility accounts (root, sync, shutdown, halt):

$ awk -F: '(($3 > 0 && $3 < 1000) && $1 !~ /^(halt|sync|shutdown)$/ && $7 !~ /(nologin|false)$/) {print $1 ":" $3 ":" $7}' /etc/passwd

If the command returns any output, this is a finding.

If any system account (other than the root account) has a login shell and it is not documented with the information system security officer (ISSO), this is a finding.

Fix

Configure OL 8 so that all noninteractive accounts on the system do not have an interactive shell assigned to them.

If the system account needs a shell assigned for mission operations, document the need with the ISSO.

Run the following command to disable the interactive shell for a specific noninteractive user account:

$ sudo usermod --shell /usr/sbin/nologin <user>

Identifiers

Group ID
V-288824
Group title
SRG-OS-000480-GPOS-00227
Rule ID
SV-288824r1261628_rule
Check ID
C-93513r1261626_chk
Fix ID
F-93418r1261627_fix