SV-235853r627686_rule
V-235853
SRG-APP-000516
DKER-EE-005190
CAT I
10
Step 1: Find out the file location:
systemctl show -p FragmentPath docker.socket
Step 2: If the file exists, execute the below command with the correct file path to set the ownership and group ownership for the file to root.
Example:
chown root:root /usr/lib/systemd/system/docker.socket
Ensure that docker.socket file ownership is set to root:root.
Step 1: Find out the file location:
systemctl show -p FragmentPath docker.socket
Step 2: If the file does not exist, this is not a finding. If the file exists, execute the below command with the correct file path to verify that the file is owned and group-owned by root.
Example:
stat -c %U:%G /usr/lib/systemd/system/docker.socket | grep -v root:root
If the above command returns nothing, this is not a finding. If the command returns non root:root file permissions, this is a finding.
V-235853
False
DKER-EE-005190
Ensure that docker.socket file ownership is set to root:root.
Step 1: Find out the file location:
systemctl show -p FragmentPath docker.socket
Step 2: If the file does not exist, this is not a finding. If the file exists, execute the below command with the correct file path to verify that the file is owned and group-owned by root.
Example:
stat -c %U:%G /usr/lib/systemd/system/docker.socket | grep -v root:root
If the above command returns nothing, this is not a finding. If the command returns non root:root file permissions, this is a finding.
M
5281