SV-227065r603265_rule
V-227065
SRG-OS-000480
GEN008160
CAT II
10
Change the group ownership of the certificate database files.
# chgrp root /var/ldap/cert8.db /var/ldap/key3.db /var/ldap/secmod.db
Check if the system is using NSS LDAP.
# grep -v '^#' /etc/nsswitch.conf | grep ldap
If no lines are returned, this vulnerability is not applicable.
Verify the group ownership of the certificate database files.
# ls -lL /var/ldap/cert8.db /var/ldap/key3.db /var/ldap/secmod.db
If the group owner of any of the files is not root, bin, or sys, this is a finding.
V-227065
False
GEN008160
Check if the system is using NSS LDAP.
# grep -v '^#' /etc/nsswitch.conf | grep ldap
If no lines are returned, this vulnerability is not applicable.
Verify the group ownership of the certificate database files.
# ls -lL /var/ldap/cert8.db /var/ldap/key3.db /var/ldap/secmod.db
If the group owner of any of the files is not root, bin, or sys, this is a finding.
M
4060