Draft CIS Benchmark 1.1.3 (Level 2 Control)
Description
The user account under which NGINX runs should not have a valid password, but should be locked.
Rationale
As a defense-in-depth measure the NGINX user account should be locked to prevent logins, and to prevent a user from su-ing to nginx using the password. In general there shouldn't be a need for anyone to have to su as nginx, and when there is a need, then sudo should be used instead, which would not require the nginx account password.
Remediation
Use the passwd command to lock the nginx account: # passwd -l nginx
Audit
Ensure the nginx account is locked using the following: # passwd -S nginx The results will be similar to the following: nginx LK 2016-06-23 0 99999 7 -1 (Password locked.) or nginx L 06/23/2016 -1 -1 -1 -1
Description
The user account under which NGINX runs should not have a valid password, but should be locked.
Rationale
As a defense-in-depth measure the NGINX user account should be locked to prevent logins, and to prevent a user from su-ing to
nginxusing the password. In general there shouldn't be a need for anyone to have tosuasnginx, and when there is a need, thensudoshould be used instead, which would not require thenginxaccount password.Remediation
Use the
passwdcommand to lock thenginxaccount:# passwd -l nginxAudit
Ensure the
nginxaccount is locked using the following:# passwd -S nginxThe results will be similar to the following:nginx LK 2016-06-23 0 99999 7 -1 (Password locked.)ornginx L 06/23/2016 -1 -1 -1 -1