This is not the latest version of the STIG. This is provided for archival purposes. See the latest STIG.

RHEL 10 must not allow duplicate user IDs (UIDs) to exist for interactive users.

STIG ID: RHEL-10-600130  |  SRG: SRG-OS-000104-GPOS-00051 |  Severity: medium (CAT II)  |  CCI: CCI-000764,CCI-000804 |  Vulnerability Id: V-281172

Vulnerability Discussion

To ensure accountability and prevent unauthenticated access, interactive users must be identified and authenticated to prevent potential misuse and compromise of the system.

Satisfies: SRG-OS-000104-GPOS-00051, SRG-OS-000121-GPOS-00062

Check

Verify RHEL 10 contains no duplicate UIDs for interactive users with the following command:

$ sudo awk -F ":" 'list[$3]++{print $1, $3}' /etc/passwd

If output is produced and the accounts listed are interactive user accounts, this is a finding.

Fix

Configure RHEL 10 to not allow duplicate UIDs to exist for interactive users.

Edit the file "/etc/passwd", and provide each interactive user account that has a duplicate UID with a unique UID.