Check: RHEL-07-021110
RHEL 7 STIG:
RHEL-07-021110
(in versions v3 r15 through v1 r1)
Title
The Red Hat Enterprise Linux operating system must be configured so that the cron.allow file, if it exists, is owned by root. (Cat II impact)
Discussion
If the owner of the "cron.allow" file is not set to root, the possibility exists for an unauthorized user to view or to edit sensitive information.
Check Content
Verify that the "cron.allow" file is owned by root. Check the owner of the "cron.allow" file with the following command: # ls -al /etc/cron.allow -rw------- 1 root root 6 Mar 5 2011 /etc/cron.allow If the "cron.allow" file exists and has an owner other than root, this is a finding.
Fix Text
Set the owner on the "/etc/cron.allow" file to root with the following command: # chown root /etc/cron.allow
Additional Identifiers
Rule ID: SV-204490r991589_rule
Vulnerability ID: V-204490
Group Title: SRG-OS-000480-GPOS-00227
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000366 |
Implement the security configuration settings. |
Controls
Number | Title |
---|---|
CM-6 |
Configuration Settings |