From 21222ff119035d503987069d39dd4d567b81e6b3 Mon Sep 17 00:00:00 2001 From: Josh Patterson Date: Fri, 25 Sep 2026 09:23:09 -0400 Subject: [PATCH] FIX: use /sbin/nologin for service accounts These accounts existed only for container UID mapping and filesystem ownership, but user.present omitted shell:, so Salt fell through to the platform useradd default and every one of them got /bin/bash. Pin them to /sbin/nologin so none can be used as an interactive login or `su -` target. socore keeps /bin/bash: `su socore -c '/usr/sbin/so-repo-sync'` in soup and so-kernel-upgrade execs the account's passwd shell, and operator docs tell users to su to socore. soqemussh keeps /bin/bash as an SSH login account. elastic-agent, elastic-agent-pr and kafka are included alongside the accounts named in the issue, being the same class with the same unset shell, so the default is uniform. Cron is unaffected: cronie runs jobs via the crontab SHELL (default /bin/sh), not the passwd shell. suricata is the only account changed here that owns a crontab, and somon has shipped as nologin with a working cron job already. The zeek `runuser -l zeek` calls all run inside so-zeek via docker.run/exec, so they resolve the shell from the image, not the host. Verified on a 3.4.0 managersearch + sensor grid: highstate converges with the shell as the only change and no failures, is idempotent on a second run, all containers stay up, SOC still issues a Kratos login flow, and the suricata surilogcompress cron job runs post-change ((suricata) CMD/CMDEND in /var/log/cron) while `su - suricata` is now refused. Closes #16256 --- salt/elastalert/config.sls | 1 + salt/elastic-fleet-package-registry/config.sls | 1 + salt/elasticagent/config.sls | 1 + salt/elasticfleet/config.sls | 1 + salt/elasticsearch/config.sls | 1 + salt/kafka/config.sls | 1 + salt/kibana/config.sls | 1 + salt/kratos/config.sls | 1 + salt/logstash/config.sls | 1 + salt/suricata/config.sls | 1 + salt/zeek/config.sls | 1 + 11 files changed, 11 insertions(+) diff --git a/salt/elastalert/config.sls b/salt/elastalert/config.sls index 147666e6e..f75cbc1a4 100644 --- a/salt/elastalert/config.sls +++ b/salt/elastalert/config.sls @@ -21,6 +21,7 @@ elastalert: - gid: 933 - home: /opt/so/conf/elastalert - createhome: False + - shell: /sbin/nologin elastalogdir: file.directory: diff --git a/salt/elastic-fleet-package-registry/config.sls b/salt/elastic-fleet-package-registry/config.sls index aa2872069..f49d9ba7b 100644 --- a/salt/elastic-fleet-package-registry/config.sls +++ b/salt/elastic-fleet-package-registry/config.sls @@ -19,6 +19,7 @@ elastic-agent-pr: - gid: 948 - home: /opt/so/conf/elastic-fleet-pr - createhome: False + - shell: /sbin/nologin {% else %} diff --git a/salt/elasticagent/config.sls b/salt/elasticagent/config.sls index 63992b199..f572515eb 100644 --- a/salt/elasticagent/config.sls +++ b/salt/elasticagent/config.sls @@ -20,6 +20,7 @@ elastic-agent: - gid: 949 - home: /opt/so/conf/elastic-agent - createhome: False + - shell: /sbin/nologin elasticagentconfdir: file.directory: diff --git a/salt/elasticfleet/config.sls b/salt/elasticfleet/config.sls index 59f052b7f..d5dc3595d 100644 --- a/salt/elasticfleet/config.sls +++ b/salt/elasticfleet/config.sls @@ -26,6 +26,7 @@ elastic-fleet: - gid: 947 - home: /opt/so/conf/elastic-fleet - createhome: False + - shell: /sbin/nologin elasticfleet_sbin: file.recurse: diff --git a/salt/elasticsearch/config.sls b/salt/elasticsearch/config.sls index 5c1645ca6..d7a5c0439 100644 --- a/salt/elasticsearch/config.sls +++ b/salt/elasticsearch/config.sls @@ -32,6 +32,7 @@ elasticsearch: - gid: 930 - home: /opt/so/conf/elasticsearch - createhome: False + - shell: /sbin/nologin elasticsearch_sbin: file.recurse: diff --git a/salt/kafka/config.sls b/salt/kafka/config.sls index 6a7c30c94..10caf8ec5 100644 --- a/salt/kafka/config.sls +++ b/salt/kafka/config.sls @@ -21,6 +21,7 @@ kafka_user: - gid: 960 - home: /opt/so/conf/kafka - createhome: False + - shell: /sbin/nologin kafka_home_dir: file.absent: diff --git a/salt/kibana/config.sls b/salt/kibana/config.sls index bc4e5f431..4638f8b75 100644 --- a/salt/kibana/config.sls +++ b/salt/kibana/config.sls @@ -22,6 +22,7 @@ kibana: - gid: 932 - home: /opt/so/conf/kibana - createhome: False + - shell: /sbin/nologin # Drop the correct nginx config based on role diff --git a/salt/kratos/config.sls b/salt/kratos/config.sls index 622522e0b..d9a963920 100644 --- a/salt/kratos/config.sls +++ b/salt/kratos/config.sls @@ -27,6 +27,7 @@ kratos: - uid: 928 - gid: 928 - home: /opt/so/conf/kratos + - shell: /sbin/nologin kratosdir: file.directory: diff --git a/salt/logstash/config.sls b/salt/logstash/config.sls index 7a09349fc..bbd5bf041 100644 --- a/salt/logstash/config.sls +++ b/salt/logstash/config.sls @@ -35,6 +35,7 @@ logstash: - uid: 931 - gid: 931 - home: /opt/so/conf/logstash + - shell: /sbin/nologin logstash_sbin: file.recurse: diff --git a/salt/suricata/config.sls b/salt/suricata/config.sls index dd228ef31..9b78f8907 100644 --- a/salt/suricata/config.sls +++ b/salt/suricata/config.sls @@ -64,6 +64,7 @@ suricata: - gid: 940 - home: /nsm/suricata - createhome: False + - shell: /sbin/nologin socoregroupwithsuricata: group.present: diff --git a/salt/zeek/config.sls b/salt/zeek/config.sls index 17a495010..ccf51a3f6 100644 --- a/salt/zeek/config.sls +++ b/salt/zeek/config.sls @@ -23,6 +23,7 @@ zeek: - gid: 937 - home: /opt/so/conf/zeek - createhome: False + - shell: /sbin/nologin # Create some directories zeekpolicydir: