STIGUI
V-282356CAT II — Medium severitySV-282356r1200048_rule

TOSS 5 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/gshadow.

Rule version TOSS-05-000455 · STIG v1 · 2026-08-20

Discussion

In addition to auditing new user and group accounts, these watches will alert the system administrator(s) to any modifications. Any unexpected users, groups, or modifications should be investigated for legitimacy.

Satisfies: SRG-OS-000004-GPOS-00004, SRG-OS-000037-GPOS-00015, SRG-OS-000042-GPOS-00020, SRG-OS-000062-GPOS-00031, SRG-OS-000239-GPOS-00089, SRG-OS-000240-GPOS-00090, SRG-OS-000241-GPOS-00091, SRG-OS-000303-GPOS-00120, SRG-OS-000304-GPOS-00121, SRG-OS-000392-GPOS-00172, SRG-OS-000462-GPOS-00206, SRG-OS-000466-GPOS-00210, SRG-OS-000470-GPOS-00214, SRG-OS-000471-GPOS-00215, SRG-OS-000476-GPOS-00221

Check

Verify TOSS 5 generates audit records for all account creations, modifications, disabling, and termination events that affect "/etc/gshadow" using the following command:

$ sudo auditctl -l | egrep '(/etc/gshadow)' 

-w /etc/gshadow -p wa -k identity

If the command does not return a line or the line is commented out, this is a finding.

Fix

Configure TOSS 5 to generate audit records for all account creations, modifications, disabling, and termination events that affect "/etc/gshadow".

Add or update the following file system rule to "/etc/audit/rules.d/audit.rules":

-w /etc/gshadow -p wa -k identity

Restart the audit daemon for the changes to take effect.

Identifiers

Group ID
V-282356
Group title
SRG-OS-000004-GPOS-00004
Rule ID
SV-282356r1200048_rule
Check ID
C-86917r1200046_chk
Fix ID
F-86822r1200047_fix