Check: GEN000930
Solaris 9 X86 STIG:
GEN000930
(in version v1 r9)
Title
The root account's home directory must not have an extended ACL. (Cat II impact)
Discussion
File system extended ACLs provide access to files beyond what is allowed by the mode numbers of the files.
Check Content
Verify the root account's home directory has no extended ACL. # ls -ld ~root If the permissions include a "+", the directory has an extended ACL and this is a finding.
Fix Text
Remove the extended ACL on the root account's home directory. # getfacl ~root Remove each ACE returned. # setfacl -d [ACE] ~root
Additional Identifiers
Rule ID: SV-26352r1_rule
Vulnerability ID: V-22309
Group Title:
Expert Comments
Expert comments are only available to logged-in users.
CCIs
CCIs tied to check.
Number | Definition |
---|---|
CCI-000225 |
Employ the principle of least privilege, allowing only authorized accesses for users (or processes acting on behalf of users) which are necessary to accomplish assigned organizational tasks. |
Controls
Controls tied to check. These are derived from the CCIs shown above.
Number | Title |
---|---|
AC-6 |
Least Privilege |