UCF STIG Viewer Logo

All interactive user home directories defined in the /etc/passwd file must exist.


Overview

Finding ID Version Rule ID IA Controls Severity
V-900 GEN001460 SV-38489r2_rule ECSC-1 Low
Description
If a user has a home directory defined that does not exist, the user may be given the / directory, by default, as the current working directory upon logon. This could create a Denial of Service because the user would not be able to perform useful tasks in this location.
STIG Date
HP-UX 11.31 Security Technical Implementation Guide 2018-09-14

Details

Check Text ( C-36334r3_chk )
Verify the consistency of the assigned home directories in the authentication database.
For Trusted Mode:
# authck -av

If any assigned home directory does not exist, this is a finding.

For SMSE:
# pwck

If any assigned home directory does not exist, this is a finding.
Fix Text (F-31589r2_fix)
Determine why the user home directory does not exist. Possible actions include: account deletion or disablement. If the account is determined to be valid, create the home directory either manually (mkdir directoryname, copy the skeleton files into the directory, chown account name for the new directory and the skeleton files) or via the HP SMH/SAM utility.