UCF STIG Viewer Logo

The root user's home directory must not be the root directory (/).


Overview

Finding ID Version Rule ID IA Controls Severity
GEN000900-ESXI5-PF GEN000900-ESXI5-PF GEN000900-ESXI5-PF_rule Low
Description
Changing the root home directory to something other than / and assigning it a 0700 protection makes it more difficult for intruders to manipulate the system by reading the files that root places in its default directory. It also gives root the same discretionary access control for root's home directory as for the other plain user home directories. Permanent not a finding - No configurable LVM for the base OS file system. Root's home directory is in /.
STIG Date
VMware ESXi v5 Security Technical Implementation Guide 2013-01-15

Details

Check Text ( C-GEN000900-ESXI5-PF_chk )
ESXi does not support this requirement. This is a permanent finding.
Fix Text (F-GEN000900-ESXI5-PF_fix)
This requirement is a permanent finding and cannot be fixed. An appropriate mitigation for the system must be implemented but this finding cannot be considered fixed.