SV-216452r603267_rule
V-216452
SRG-OS-000480
SOL-11.1-080100
CAT II
10
The root role is required.
This action applies to the global zone only. Determine the zone that you are currently securing.
# zonename
If the command output is "global", this action applies.
Determine the location of the system dump directory.
# dumpadm | grep directory
Change the group-owner of the kernel core dump data directory.
# chgrp root [kernel core dump data directory]
In Solaris 11, /var/crash is linked to /var/share/crash.
The root role is required.
This check applies to the global zone only. Determine the zone that you are currently securing.
# zonename
If the command output is "global", this check applies.
Determine the location of the system dump directory.
# dumpadm | grep directory
Check ownership of the core dump data directory.
# ls -l [savecore directory]
If the directory is not group-owned by root, this is a finding.
In Solaris 11, /var/crash is linked to /var/share/crash.
V-216452
False
SOL-11.1-080100
The root role is required.
This check applies to the global zone only. Determine the zone that you are currently securing.
# zonename
If the command output is "global", this check applies.
Determine the location of the system dump directory.
# dumpadm | grep directory
Check ownership of the core dump data directory.
# ls -l [savecore directory]
If the directory is not group-owned by root, this is a finding.
In Solaris 11, /var/crash is linked to /var/share/crash.
M
4022