Ensuring shells are not given to system accounts upon login makes it more difficult for attackers to make use of system accounts.
Check
Verify OL 8 system accounts do not have an interactive login shell.
Run the following command to list any system account (UID < 1000) that has an interactive shell, excluding authorized system utility accounts (root, sync, shutdown, halt):
If the command returns any output, this is a finding.
If any system account (other than the root account) has a login shell and it is not documented with the information system security officer (ISSO), this is a finding.
Fix
Configure OL 8 so that all noninteractive accounts on the system do not have an interactive shell assigned to them.
If the system account needs a shell assigned for mission operations, document the need with the ISSO.
Run the following command to disable the interactive shell for a specific noninteractive user account: