mirror of
https://github.com/Security-Onion-Solutions/securityonion.git
synced 2026-10-08 15:25:26 +02:00
FIX: use /sbin/nologin for service accounts
These accounts existed only for container UID mapping and filesystem ownership, but user.present omitted shell:, so Salt fell through to the platform useradd default and every one of them got /bin/bash. Pin them to /sbin/nologin so none can be used as an interactive login or `su -` target. socore keeps /bin/bash: `su socore -c '/usr/sbin/so-repo-sync'` in soup and so-kernel-upgrade execs the account's passwd shell, and operator docs tell users to su to socore. soqemussh keeps /bin/bash as an SSH login account. elastic-agent, elastic-agent-pr and kafka are included alongside the accounts named in the issue, being the same class with the same unset shell, so the default is uniform. Cron is unaffected: cronie runs jobs via the crontab SHELL (default /bin/sh), not the passwd shell. suricata is the only account changed here that owns a crontab, and somon has shipped as nologin with a working cron job already. The zeek `runuser -l zeek` calls all run inside so-zeek via docker.run/exec, so they resolve the shell from the image, not the host. Verified on a 3.4.0 managersearch + sensor grid: highstate converges with the shell as the only change and no failures, is idempotent on a second run, all containers stay up, SOC still issues a Kratos login flow, and the suricata surilogcompress cron job runs post-change ((suricata) CMD/CMDEND in /var/log/cron) while `su - suricata` is now refused. Closes #16256
This commit is contained in:
11 files changed
+11
No files matched your search
@@ -21,6 +21,7 @@ elastalert:
|
||||
- gid: 933
|
||||
- home: /opt/so/conf/elastalert
|
||||
- createhome: False
|
||||
- shell: /sbin/nologin
|
||||
|
||||
elastalogdir:
|
||||
file.directory:
|
||||
|
||||
@@ -19,6 +19,7 @@ elastic-agent-pr:
|
||||
- gid: 948
|
||||
- home: /opt/so/conf/elastic-fleet-pr
|
||||
- createhome: False
|
||||
- shell: /sbin/nologin
|
||||
|
||||
{% else %}
|
||||
|
||||
|
||||
@@ -20,6 +20,7 @@ elastic-agent:
|
||||
- gid: 949
|
||||
- home: /opt/so/conf/elastic-agent
|
||||
- createhome: False
|
||||
- shell: /sbin/nologin
|
||||
|
||||
elasticagentconfdir:
|
||||
file.directory:
|
||||
|
||||
@@ -26,6 +26,7 @@ elastic-fleet:
|
||||
- gid: 947
|
||||
- home: /opt/so/conf/elastic-fleet
|
||||
- createhome: False
|
||||
- shell: /sbin/nologin
|
||||
|
||||
elasticfleet_sbin:
|
||||
file.recurse:
|
||||
|
||||
@@ -32,6 +32,7 @@ elasticsearch:
|
||||
- gid: 930
|
||||
- home: /opt/so/conf/elasticsearch
|
||||
- createhome: False
|
||||
- shell: /sbin/nologin
|
||||
|
||||
elasticsearch_sbin:
|
||||
file.recurse:
|
||||
|
||||
@@ -21,6 +21,7 @@ kafka_user:
|
||||
- gid: 960
|
||||
- home: /opt/so/conf/kafka
|
||||
- createhome: False
|
||||
- shell: /sbin/nologin
|
||||
|
||||
kafka_home_dir:
|
||||
file.absent:
|
||||
|
||||
@@ -22,6 +22,7 @@ kibana:
|
||||
- gid: 932
|
||||
- home: /opt/so/conf/kibana
|
||||
- createhome: False
|
||||
- shell: /sbin/nologin
|
||||
|
||||
# Drop the correct nginx config based on role
|
||||
|
||||
|
||||
@@ -27,6 +27,7 @@ kratos:
|
||||
- uid: 928
|
||||
- gid: 928
|
||||
- home: /opt/so/conf/kratos
|
||||
- shell: /sbin/nologin
|
||||
|
||||
kratosdir:
|
||||
file.directory:
|
||||
|
||||
@@ -35,6 +35,7 @@ logstash:
|
||||
- uid: 931
|
||||
- gid: 931
|
||||
- home: /opt/so/conf/logstash
|
||||
- shell: /sbin/nologin
|
||||
|
||||
logstash_sbin:
|
||||
file.recurse:
|
||||
|
||||
@@ -64,6 +64,7 @@ suricata:
|
||||
- gid: 940
|
||||
- home: /nsm/suricata
|
||||
- createhome: False
|
||||
- shell: /sbin/nologin
|
||||
|
||||
socoregroupwithsuricata:
|
||||
group.present:
|
||||
|
||||
@@ -23,6 +23,7 @@ zeek:
|
||||
- gid: 937
|
||||
- home: /opt/so/conf/zeek
|
||||
- createhome: False
|
||||
- shell: /sbin/nologin
|
||||
|
||||
# Create some directories
|
||||
zeekpolicydir:
|
||||
|
||||
Reference in new issue
Block a user