SV-227620r603266_rule
V-227620
SRG-OS-000206
GEN001270
CAT II
10
Remove the extended ACL from the file.
# chmod A- [file with extended ACL]
Verify all system log files have no extended ACLs.
Procedure:
# ls -lL /var/adm
If the permissions include a "+", the file has an extended ACL. If an extended ACL exists, verify with the SA if the ACL is required to support authorized software and provides the minimum necessary permissions. If an extended ACL exists that provides access beyond the needs of authorized software, this is a finding.
V-227620
False
GEN001270
Verify all system log files have no extended ACLs.
Procedure:
# ls -lL /var/adm
If the permissions include a "+", the file has an extended ACL. If an extended ACL exists, verify with the SA if the ACL is required to support authorized software and provides the minimum necessary permissions. If an extended ACL exists that provides access beyond the needs of authorized software, this is a finding.
M
4061