SV-227838r603266_rule
V-227838
SRG-OS-000312
GEN004380
CAT II
10
Change the mode of the /etc/mail/aliases files (or equivalent, such as /usr/lib/aliases) to 0644.
Procedure:
# chmod 0644 /etc/mail/aliases /etc/mail/aliases.db
Find the alias files on the system.
Procedure:
# egrep '^O(A| AliasFile)' /etc/mail/sendmail.cf
If the alias file is an NIS or LDAP map, this check is not applicable. The default location is /etc/mail/aliases.
Check the permissions of the alias file and the hashed version of it used by sendmail.
Procedure:
# ls -lL /etc/mail/aliases /etc/mail/aliases.db
If the alias files have a mode more permissive than 0644, this is a finding.
V-227838
False
GEN004380
Find the alias files on the system.
Procedure:
# egrep '^O(A| AliasFile)' /etc/mail/sendmail.cf
If the alias file is an NIS or LDAP map, this check is not applicable. The default location is /etc/mail/aliases.
Check the permissions of the alias file and the hashed version of it used by sendmail.
Procedure:
# ls -lL /etc/mail/aliases /etc/mail/aliases.db
If the alias files have a mode more permissive than 0644, this is a finding.
M
4061