Bug 2228460

Summary: system account with uid >= 1000 is badly detected as user interactive account [rhel-8.8.0.z]
Product: Red Hat Enterprise Linux 8 Reporter: RHEL Program Management Team <pgm-rhel-tools>
Component: scap-security-guideAssignee: Marcus Burghardt <maburgha>
Status: MODIFIED --- QA Contact: BaseOS QE Security Team <qe-baseos-security>
Severity: medium Docs Contact:
Priority: medium    
Version: 8.7CC: ggasparb, jcerny, maburgha, matyc, mhaicman, mlysonek, peter.vreman, rmetrich, vpolasek, wsato
Target Milestone: rcKeywords: Triaged, ZStream
Target Release: ---   
Hardware: x86_64   
OS: Linux   
Whiteboard:
Fixed In Version: scap-security-guide-0.1.69-1.el8_8 Doc Type: Enhancement
Doc Text:
Feature: Extend the criteria used for selecting interactive users in order to avoid special users without shell to be considered interactive users. Reason: Rules related to interactive users where considering any user with uid >= 1000 as interactive users. However, there are valid cases where users with uid >= 1000 have no interactive shell and therefore should not be considered interactive users. Result: All rules related to interactive users are aligned using the same criteria to identify interactive users in a system. These criteria are: - uid >= 1000 - except nobody and nfsnobody users - except users with /sbin/nologin shell
Story Points: ---
Clone Of: 2178740 Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2178740    
Bug Blocks: