SV-209041r603263_rule
V-209041
SRG-OS-000037
OL6-00-000339
CAT III
10
Add or correct the following configuration options within the "vsftpd" configuration file, located at "/etc/vsftpd/vsftpd.conf".
xferlog_enable=YES
xferlog_std_format=NO
log_ftp_protocol=YES
Verify the "vsftpd" package is installed:
# rpm -qa | grep -i vsftpd
vsftpd-3.0.2-22.e16.x86_64
If the "vsftpd" package is not installed, this is Not Applicable.
Find if logging is applied to the ftp daemon.
Procedures:
If vsftpd is started by xinetd the following command will indicate the xinetd.d startup file.
# grep vsftpd /etc/xinetd.d/*
# grep server_args [vsftpd xinetd.d startup file]
This will indicate the vsftpd config file used when starting through xinetd. If the [server_args]line is missing or does not include the vsftpd configuration file, then the default config file (/etc/vsftpd/vsftpd.conf) is used.
# grep xferlog_enable [vsftpd config file]
If xferlog_enable is missing, or is not set to yes, this is a finding.
V-209041
False
OL6-00-000339
Verify the "vsftpd" package is installed:
# rpm -qa | grep -i vsftpd
vsftpd-3.0.2-22.e16.x86_64
If the "vsftpd" package is not installed, this is Not Applicable.
Find if logging is applied to the ftp daemon.
Procedures:
If vsftpd is started by xinetd the following command will indicate the xinetd.d startup file.
# grep vsftpd /etc/xinetd.d/*
# grep server_args [vsftpd xinetd.d startup file]
This will indicate the vsftpd config file used when starting through xinetd. If the [server_args]line is missing or does not include the vsftpd configuration file, then the default config file (/etc/vsftpd/vsftpd.conf) is used.
# grep xferlog_enable [vsftpd config file]
If xferlog_enable is missing, or is not set to yes, this is a finding.
M
2928