Rule version TOSS-05-000296 · STIG v1 · 2026-08-20
Ensuring shells are not given to system accounts upon login makes it more difficult for attackers to make use of system accounts.
Verify that TOSS 5 system accounts do not have an interactive login shell.
Run the following command to list any system account (UID < 1000) that has an interactive shell, excluding authorized system utility accounts (root, sync, shutdown, halt):
$ $ awk -F: '(($3 > 0 && $3 < 1000) && $1 !~ /^(halt|sync|shutdown)$/ && $7 !~ /(nologin|false)$/) {print $1 ":" $3 ":" $7}' /etc/passwdIf the command returns any output, this is a finding.
Configure TOSS 5 so that all noninteractive accounts on the system do not have an interactive shell assigned to them.
If the system account needs a shell assigned for mission operations, document the need with the information system security officer (ISSO).
Run the following command to disable the interactive shell for a specific noninteractive user account:
Replace <user> with the user that has a login shell.
$ sudo usermod --shell /sbin/nologin <user>
Do not perform the steps in this section on the root account. Doing so will cause the system to become inaccessible.