diff --git a/tests/hardening/6.2.15_find_passwd_group_inconsistencies.sh b/tests/hardening/6.2.15_find_passwd_group_inconsistencies.sh index b333419..8e1da73 100644 --- a/tests/hardening/6.2.15_find_passwd_group_inconsistencies.sh +++ b/tests/hardening/6.2.15_find_passwd_group_inconsistencies.sh @@ -6,5 +6,15 @@ test_audit() { # shellcheck disable=2154 run blank /opt/debian-cis/bin/hardening/"${script}".sh --audit-all - # TODO fill comprehensive tests + local test_user="testpasswdgroupuser" + local dir="/etc/passwd" + + describe Tests purposely failing + echo "$test_user:x:1100:1100::/home/$test_user:" >> $dir + register_test retvalshouldbe 1 + register_test contain "is referenced by /etc/passwd but does not exist in /etc/group" + run noncompliant /opt/debian-cis/bin/hardening/"${script}".sh --audit-all + + # cleanup + userdel $test_user }