SV-221737r603260_rule
V-221737
SRG-OS-000480-GPOS-00227
OL07-00-020710
CAT II
10
Set the mode of the local initialization files to "0740" with the following command:
Note: The example will be for the "smithj" user, who has a home directory of "/home/smithj".
# chmod 0740 /home/smithj/.[^.]*
Verify that all local initialization files have a mode of "0740" or less permissive.
Check the mode on all local initialization files with the following command:
Note: The example will be for the "smithj" user, who has a home directory of "/home/smithj".
# ls -al /home/smithj/.[^.]* | more
-rwxr----- 1 smithj users 896 Mar 10 2011 .profile
-rwxr----- 1 smithj users 497 Jan 6 2007 .login
-rwxr----- 1 smithj users 886 Jan 6 2007 .something
If any local initialization files have a mode more permissive than "0740", this is a finding.
V-221737
False
OL07-00-020710
Verify that all local initialization files have a mode of "0740" or less permissive.
Check the mode on all local initialization files with the following command:
Note: The example will be for the "smithj" user, who has a home directory of "/home/smithj".
# ls -al /home/smithj/.[^.]* | more
-rwxr----- 1 smithj users 896 Mar 10 2011 .profile
-rwxr----- 1 smithj users 497 Jan 6 2007 .login
-rwxr----- 1 smithj users 886 Jan 6 2007 .something
If any local initialization files have a mode more permissive than "0740", this is a finding.
M
4089