UCF STIG Viewer Logo

The system must be integrated into a directory services infrastructure.


Overview

Finding ID Version Rule ID IA Controls Severity
V-59791 AOSX-10-002060 SV-74221r1_rule Medium
Description
Distinct user account databases on each separate system cause problems with username and password policy enforcement. Most approved directory services infrastructure solutions, such as Active Directory, allow centralized management of users and passwords.
STIG Date
Apple OS X 10.10 (Yosemite) Workstation Security Technical Implementation Guide 2017-04-06

Details

Check Text ( C-60547r1_chk )
To determine if the system is integrated to a directory server, ask the SA or ISSO or run the following command:

sudo dscl localhost -list . | grep -vE '(Contact | Search | Local)'

If nothing is returned, or if the system is not integrated into a directory service infrastructure, this is a finding.
Fix Text (F-65201r1_fix)
Integrate the system into an existing directory services infrastructure, such as Active Directory.