SV-215324r508663_rule
V-215324
SRG-OS-000206-GPOS-00084
AIX7-00-003007
CAT II
10
Remove the extended ACL(s) from the system log file(s):
# acledit <system_log_file>
Set "extended permissions" to "disabled".
With the assistance of the system administrator, identify all of the system log files.
For each system log file identified, verify that extended ACL's are disabled:
#aclget <system_log_file>
*
* ACL_type AIXC
*
attributes:
base permissions
owner(root): rw-
group(system): r--
others: r--
extended permissions
disabled
If "extended permissions" is set to "enabled" and is not documented, this is a finding.
V-215324
False
AIX7-00-003007
With the assistance of the system administrator, identify all of the system log files.
For each system log file identified, verify that extended ACL's are disabled:
#aclget <system_log_file>
*
* ACL_type AIXC
*
attributes:
base permissions
owner(root): rw-
group(system): r--
others: r--
extended permissions
disabled
If "extended permissions" is set to "enabled" and is not documented, this is a finding.
M
4012