Skip to content

6.2.3 Ensure all groups in /etc/passwd exist in /etc/group

Audit#

Run the following script and verify no results are returned:

1
2
3
4
5
6
7
#!/bin/bash
for i in $(cut -s -d: -f4 /etc/passwd | sort -u ); do
 grep -q -P "^.*?:[^:]*:$i:" /etc/group
 if [ $? -ne 0 ]; then
 echo "Group $i is referenced by /etc/passwd but does not exist in /etc/group"
 fi
done

Remediation#

Analyze the output of the Audit step above and perform the appropriate action to correct any discrepancies found.