RHEL 9 /etc/passwd- file must be owned by root.
Overview
Finding ID
Version
Rule ID
IA Controls
Severity
V-257908
RHEL-09-232140
SV-257908r991589_rule
Medium
Description
The "/etc/passwd-" file is a backup file of "/etc/passwd", and as such, contains information about the users that are configured on the system. Protection of this file is critical for system security.
Details
Check Text (C-61649r925709_chk)
Verify the ownership of the "/etc/passwd-" file with the following command:
$ sudo stat -c "%U %n" /etc/passwd-
root /etc/passwd-
If "/etc/passwd-" file does not have an owner of "root", this is a finding.
Fix Text (F-61573r925710_fix)
Change the owner of the file /etc/passwd- to root by running the following command:
$ sudo chown root /etc/passwd-
A comprehensive tool for accessing, analyzing, and implementing
Defense Information Systems Agency (DISA) Security Technical
Implementation Guides (STIGs).
Featured Partners
Web page built by Cyber Protection Services. To learn more about our services, click here .
© 2025 DISA STIGS Viewer. All rights reserved.