mirror of https://github.com/CISOfy/lynis.git
[AUTH-9229] added option to look for LOCKED accounts
This commit is contained in:
parent
610f70d5aa
commit
36f86d76c4
|
@ -293,8 +293,8 @@
|
|||
if [ -e ${ROOTDIR}etc/shadow ]; then SHADOW="${ROOTDIR}etc/shadow"; fi
|
||||
FIND=$(${CAT_BINARY} ${ROOTDIR}etc/passwd ${SHADOW} | ${AWKBINARY} -F : '{print length($2) ":" $2 }' | while read METHOD; do
|
||||
case ${METHOD} in
|
||||
1:\* | 1:x | 0: | *:!*)
|
||||
# disabled | shadowed | no password | locked account
|
||||
1:\* | 1:x | 0: | *:!* | *LOCK*)
|
||||
# disabled | shadowed | no password | locked account (can be literal *LOCK* or something like LOCKED)
|
||||
;;
|
||||
*:\$5\$*| *:\$6\$*)
|
||||
# sha256crypt | sha512crypt: check number of rounds, should be >5000
|
||||
|
|
Loading…
Reference in New Issue