UCF STIG Viewer Logo

The /etc/shells (or equivalent) file must exist.


Overview

Finding ID Version Rule ID IA Controls Severity
GEN002120-ESXI5-000045 GEN002120-ESXI5-000045 GEN002120-ESXI5-000045_rule Medium
Description
The shells file (or equivalent) lists approved default shells. It helps provide layered defense to the security approach by ensuring users cannot change their default shell to an unauthorized shell that may not be secure.
STIG Date
VMware ESXi v5 Security Technical Implementation Guide 2013-01-15

Details

Check Text ( C-GEN002120-ESXI5-000045_chk )
Disable lock down mode. Enable the ESXi Shell.
= /etc/shells
Execute the following command(s):
# ls -l /etc/shells

If /etc/shells does not exist, this is a finding.

Re-enable lock down mode.
Fix Text (F-GEN002120-ESXI5-000045_fix)
Disable lock down mode.
Enable the ESXi Shell.
= /etc/shells
Execute the following command(s):
# > /etc/shells

Re-enable lock down mode.