SV-99273r1_rule
V-88623
SRG-OS-000239-GPOS-00089
VROM-SL-000850
CAT II
10
Configure append auditing of the "passwd", "shadow", "group", and "gshadow" files run the DoD.script with the following command as root:
# /etc/dodscript.sh
OR
Configure append auditing of the "passwd", "shadow", "group", and "gshadow" files. Add the following to the audit.rules file:
-w /etc/passwd -p w -k passwd
-w /etc/shadow -p w -k shadow
-w /etc/group -p w -k group
-w /etc/gshadow -p w -k gshadow
Restart the auditd service.
# service auditd restart
Determine if "/etc/passwd", "/etc/shadow", "/etc/group", and "/etc/gshadow" are audited for writing.
# auditctl -l | egrep '(/etc/passwd|/etc/shadow|/etc/group|/etc/gshadow)' | grep perm=w
If any of these are not listed with a permissions filter of at least "w", this is a finding.
V-88623
False
VROM-SL-000850
Determine if "/etc/passwd", "/etc/shadow", "/etc/group", and "/etc/gshadow" are audited for writing.
# auditctl -l | egrep '(/etc/passwd|/etc/shadow|/etc/group|/etc/gshadow)' | grep perm=w
If any of these are not listed with a permissions filter of at least "w", this is a finding.
M
3461