Check: GEN000930
SUSE Linux Enterprise Server v11 for System z STIG:
GEN000930
(in versions v1 r12 through v1 r9)
Title
The root accounts home directory must not have an extended ACL. (Cat II impact)
Discussion
File system extended ACLs provide access to files beyond what is allowed by the unix permissions of the files.
Check Content
Check the root account's home directory has no extended ACL. # grep "^root" /etc/passwd | awk -F":" ‘{print $6}’ # ls -ld <root home directory> If the permissions include a '+' the directory has an extended ACL. If the file has an extended ACL and it has not been documented with the IAO, this is a finding.
Fix Text
Remove the extended ACL from the root account's home directory. # setfacl --remove-all <root home directory>
Additional Identifiers
Rule ID: SV-44903r1_rule
Vulnerability ID: V-22309
Group Title: GEN000930
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000225 |
Employ the principle of least privilege, allowing only authorized accesses for users (or processes acting on behalf of users) which are necessary to accomplish assigned organizational tasks. |
Controls
Number | Title |
---|---|
AC-6 |
Least Privilege |