SV-100405r1_rule
V-89755
SRG-OS-000256-GPOS-00097
VRAU-SL-000905
CAT II
10
Run the following command to reset audit permissions to the correct values:
sudo rpm --setperms audit-1.8-0.34.26
The following command will list which audit files on the system have permissions different from what is expected by the RPM database:
# rpm -V audit | grep '^.M'
If there is any output, for each file or directory found, compare the RPM-expected permissions with the permissions on the file or directory:
# rpm -q --queryformat "[%{FILENAMES} %{FILEMODES:perms}\n]" audit | grep [filename]
# ls -lL [filename]
If the existing permissions are more permissive than those expected by RPM, this is a finding.
V-89755
False
VRAU-SL-000905
The following command will list which audit files on the system have permissions different from what is expected by the RPM database:
# rpm -V audit | grep '^.M'
If there is any output, for each file or directory found, compare the RPM-expected permissions with the permissions on the file or directory:
# rpm -q --queryformat "[%{FILENAMES} %{FILEMODES:perms}\n]" audit | grep [filename]
# ls -lL [filename]
If the existing permissions are more permissive than those expected by RPM, this is a finding.
M
3459