Skip to content

Lock the NGINX User Account #15

Description

@JJediny

Draft CIS Benchmark 1.1.3 (Level 2 Control)

Description

The user account under which NGINX runs should not have a valid password, but should be locked.

Rationale

As a defense-in-depth measure the NGINX user account should be locked to prevent logins, and to prevent a user from su-ing to nginx using the password. In general there shouldn't be a need for anyone to have to su as nginx, and when there is a need, then sudo should be used instead, which would not require the nginx account password.

Remediation

Use the passwd command to lock the nginx account: # passwd -l nginx

Audit

Ensure the nginx account is locked using the following: # passwd -S nginx The results will be similar to the following: nginx LK 2016-06-23 0 99999 7 -1 (Password locked.) or nginx L 06/23/2016 -1 -1 -1 -1

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions