SV-235851r627680_rule
V-235851
SRG-APP-000516
DKER-EE-005170
CAT I
10
Step 1: Find out the file location:
systemctl show -p FragmentPath docker.service
Step 2: If the file exists, execute the below command with the correct file path to set the ownership and group ownership for the file to root.
Example:
chown root:root /usr/lib/systemd/system/docker.service
Ensure that docker.service file ownership is set to root:root
Step 1: Find out the file location:
systemctl show -p FragmentPath docker.service
Step 2: If the file does not exist, this is not a finding. If the file exists, execute the below command with the correct file path to verify that the file is owned and group-owned by root.
Example:
stat -c %U:%G /usr/lib/systemd/system/docker.service | grep -v root:root
If the above command returns nothing, this is not a finding. If the command returns non root:root file permissions, this is a finding.
V-235851
False
DKER-EE-005170
Ensure that docker.service file ownership is set to root:root
Step 1: Find out the file location:
systemctl show -p FragmentPath docker.service
Step 2: If the file does not exist, this is not a finding. If the file exists, execute the below command with the correct file path to verify that the file is owned and group-owned by root.
Example:
stat -c %U:%G /usr/lib/systemd/system/docker.service | grep -v root:root
If the above command returns nothing, this is not a finding. If the command returns non root:root file permissions, this is a finding.
M
5281