Skip to content
Back to skills

Cis Apache 3.3

ASecurity

Ensure the Apache User Account Is Locked

  • 2,182 stars
  • 0 votes
  • 0 copies
  • 1 view
  • Added May 30, 2026
securitygo

Security analysis

A100/100

Scanned May 30, 2026

npx -y skills add CyberStrikeus/CyberStrike --skill cis-apache-3.3 --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Cis Apache 3.3?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Cis Apache 3.3
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/cyberstrikeus-cis-apache-3-3/badge)](https://www.skillsdirectory.com/skills/cyberstrikeus-cis-apache-3-3)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: cis-apache-3.3
description: "Ensure the Apache User Account Is Locked"
category: cis-apache
version: "3.6.0"
author: cyberstrike-official
tags: [cis, apache, linux, privileges, permissions, ownership]
cis_id: "3.3"
cis_benchmark: "CIS Apache HTTP Server 2.2 Benchmark v3.6.0"
tech_stack: [linux, apache]
cwe_ids: []
chains_with: []
prerequisites: []
severity_boost: {}
---

# Ensure the Apache User Account Is Locked

## Description

The user account under which Apache runs should not have a valid password, but should be locked.

## Rationale

As a defense-in-depth measure, the Apache user account should be locked to prevent logins and to prevent a user from su-ing to `apache` using the password. In general, there shouldn't be a need for anyone to have to su as `apache`, and when there is a need, `sudo` should be used instead, which would not require the `apache` account password.

## Impact

None documented

## Audit Procedure

Ensure the `apache` account is locked using the following:

```
# passwd -S apache
```

The results should be similar to the following:

```
apache LK 2010-01-28 0 99999 7 -1 (Password locked.)

- or -

apache L 07/02/2012 -1 -1 -1 -1
```

## Remediation

Use the `passwd` command to lock the `apache` account:

```
# passwd -l apache
```

## Default Value

The default user account, daemon, is locked by default.

## References

None documented

## CIS Controls

### Version 6

16 Account Monitoring and Control

Account Monitoring and Control

### Version 7

16.8 Disable Any Unassociated Accounts

Disable any account that cannot be associated with a business process or business owner.

## Profile

Level 1 | Scored

## Notes

The default user account, daemon, is locked by default.

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…