SV-216216r603268_rule
V-216216
SRG-OS-000480
SOL-11.1-080110
CAT II
10
The root role is required.
This action applies to the global zone only. Determine the zone that you are currently securing.
# zonename
If the command output is "global", this action applies.
Determine the location of the system dump directory.
# dumpadm | grep directory
Change the group-owner of the kernel core dump data directory.
# chmod 0700 [savecore directory]
The root role is required.
This check applies to the global zone only. Determine the zone that you are currently securing.
# zonename
If the command output is "global", this check applies.
Determine the location of the system dump directory.
# dumpadm | grep directory
Check the permissions of the kernel core dump data directory.
# ls -ld [savecore directory]
If the directory has a mode more permissive than 0700 (rwx --- ---), this is a finding.
V-216216
False
SOL-11.1-080110
The root role is required.
This check applies to the global zone only. Determine the zone that you are currently securing.
# zonename
If the command output is "global", this check applies.
Determine the location of the system dump directory.
# dumpadm | grep directory
Check the permissions of the kernel core dump data directory.
# ls -ld [savecore directory]
If the directory has a mode more permissive than 0700 (rwx --- ---), this is a finding.
M
4021