SV-216342r603267_rule
V-216342
SRG-OS-000480
SOL-11.1-040260
CAT III
10
The root role is required.
# pkg list service/network/ftp
If the output of this command is:
pkg list: no packages matching 'service/network/ftp' installed
no further action is required. Otherwise, edit the FTP configuration file.
# pfedit /etc/proftpd.conf
Locate the line containing:
Umask
Change the line to read:
Umask 077
The package service/network/ftp must be installed for this check.
# pkg list service/network/ftp
If the output of this command is:
pkg list: no packages matching 'service/network/ftp' installed
no further action is required.
Determine if the FTP umask is set to 077.
# egrep -i "^UMASK" /etc/proftpd.conf | awk '{ print $2 }'
If 077 is not displayed, this is a finding.
V-216342
False
SOL-11.1-040260
The package service/network/ftp must be installed for this check.
# pkg list service/network/ftp
If the output of this command is:
pkg list: no packages matching 'service/network/ftp' installed
no further action is required.
Determine if the FTP umask is set to 077.
# egrep -i "^UMASK" /etc/proftpd.conf | awk '{ print $2 }'
If 077 is not displayed, this is a finding.
M
4022