SV-226593r603265_rule
V-226593
SRG-OS-000058
GEN002710
CAT II
10
Remove the extended ACL from the file.
# chmod A- [audit file]
Check the audit configuration to determine the location of the system audit log files.
# more /etc/security/audit_control
Check the system audit log files for extended ACLs.
# ls -la [audit log dir]
If the permissions include a "+", the file has an extended ACL and this is a finding.
V-226593
False
GEN002710
Check the audit configuration to determine the location of the system audit log files.
# more /etc/security/audit_control
Check the system audit log files for extended ACLs.
# ls -la [audit log dir]
If the permissions include a "+", the file has an extended ACL and this is a finding.
M
4060