All home directories must be owned by the respective user assigned to it in /etc/passwd.
Severity | Group ID | Group Title | Version | Rule ID | Date | STIG Version |
|---|---|---|---|---|---|---|
| medium | V-216425 | SRG-OS-000480 | SOL-11.1-070090 | SV-216425r959010_rule | 2026-02-19 | 3 |
Description
Since the user is accountable for files stored in the user's home directory, the user must be the owner of the directory.
ℹ️ Check
The root role is required.
Check that home directories are owned by the correct user.
# export IFS=":"; logins -uxo | while read user uid group gid gecos home rest; do result=$(find ${home} -type d -prune \! -user $user -print 2>/dev/null);
if [ ! -z "${result}" ]; then
echo "User: ${user}\tOwner: $(ls -ld $home | awk '{ print $3 }')";
fi;
done
If any output is produced, this is a finding.
✔️ Fix
The root role is required.
Correct the owner of any directory that does not match the password file entry for that user.
# chown [user] [home directory]