SV-227839r603266_rule
V-227839
SRG-OS-000480
GEN004390
CAT II
10
Remove the extended ACL from the files.
# chmod A- /etc/mail/aliases /etc/mail/aliases.db
Find the alias files on the system.
Procedure:
# egrep '^O(A| AliasFile)' /etc/mail/sendmail.cf
If the "alias file" is an NIS or LDAP map, this check is not applicable. The default location is /etc/mail/aliases.
Check the permissions of the alias file and the hashed version of it used by sendmail.
Procedure:
# ls -lL /etc/mail/aliases /etc/mail/aliases.db
If the permissions include a "+", the file has an extended ACL and this is a finding.
V-227839
False
GEN004390
Find the alias files on the system.
Procedure:
# egrep '^O(A| AliasFile)' /etc/mail/sendmail.cf
If the "alias file" is an NIS or LDAP map, this check is not applicable. The default location is /etc/mail/aliases.
Check the permissions of the alias file and the hashed version of it used by sendmail.
Procedure:
# ls -lL /etc/mail/aliases /etc/mail/aliases.db
If the permissions include a "+", the file has an extended ACL and this is a finding.
M
4061