SV-216221r603268_rule
V-216221
SRG-OS-000480
SOL-11.1-090010
CAT II
10
The root role is required.
Solaris 11 includes the Basic Account and Reporting Tool (BART) which uses cryptographic-strength checksums and file system metadata to determine changes. By default, the manifest generator catalogs all attributes of all files in the root (/) file system. File systems mounted on the root file system are cataloged only if they are of the same type as the root file system.
Create a protected area to store BART manifests.
# mkdir /var/adm/log/bartlogs
# chmod 700 /var/adm/log/bartlogs
After initial installation and configuration of the system, create a manifest report of the current baseline.
# bart create > /var/adm/log/bartlogs/[baseline manifest filename]
The root role is required.
Solaris 11 includes the Basic Account and Reporting Tool (BART) which uses cryptographic-strength checksums and file system metadata to determine changes. By default, the manifest generator catalogs all attributes of all files in the root (/) file system. File systems mounted on the root file system are cataloged only if they are of the same type as the root file system.
A Baseline BART manifest may exist in:
/var/adm/log/bartlogs/[control manifest filename]
If a BART manifest does not exist, this is a finding.
At least weekly, create a new BART baseline report.
# bart create > /var/adm/log/bartlogs/[new manifest filename]
Compare the new report to the previous report to identify any changes in the system baseline.
# bart compare /var/adm/log/bartlogs/[baseline manifest filename> /var/adm/log/bartlogs/[new manifest filename]
Examine the BART report for changes. If there are changes to system files in /etc that are not approved, this is a finding.
V-216221
False
SOL-11.1-090010
The root role is required.
Solaris 11 includes the Basic Account and Reporting Tool (BART) which uses cryptographic-strength checksums and file system metadata to determine changes. By default, the manifest generator catalogs all attributes of all files in the root (/) file system. File systems mounted on the root file system are cataloged only if they are of the same type as the root file system.
A Baseline BART manifest may exist in:
/var/adm/log/bartlogs/[control manifest filename]
If a BART manifest does not exist, this is a finding.
At least weekly, create a new BART baseline report.
# bart create > /var/adm/log/bartlogs/[new manifest filename]
Compare the new report to the previous report to identify any changes in the system baseline.
# bart compare /var/adm/log/bartlogs/[baseline manifest filename> /var/adm/log/bartlogs/[new manifest filename]
Examine the BART report for changes. If there are changes to system files in /etc that are not approved, this is a finding.
M
4021