Check: GEN004440
HP-UX 11.31 STIG:
GEN004440
(in versions v1 r19 through v1 r13)
Title
Sendmail logging must not be set to less than 9 in the sendmail.cf file. (Cat III impact)
Discussion
If Sendmail is not configured to log at level 9, system logs may not contain the information necessary for tracking unauthorized use of the sendmail service.
Check Content
The sendmail.cf log level option line will typically appear as follows: O LogLevel=N Check if Sendmail logging is set to level 9 via the following command: # cat /etc/mail/sendmail.cf | tr '\011' ' ' | tr -s ' ' | sed -e 's/^[ \t]*//' | grep -v "^#" | \ grep -i loglevel | tr '\011' ' ' | tr -d ' ' | cut -f 2,2 -d "=" If logging is not set, i.e., line is missing or commented, this is a finding. If logging is set to less than 9, this is a finding.
Fix Text
Edit the sendmail.cf file, locate the entry (and where necessary uncomment it and/or create it) and modify/set it to 9.
Additional Identifiers
Rule ID: SV-35047r1_rule
Vulnerability ID: V-835
Group Title: GEN004440
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000366 |
The organization implements the security configuration settings. |
Controls
Number | Title |
---|---|
CM-6 |
Configuration Settings |