UCF STIG Viewer Logo

Crontab files must be group-owned by root, sys, cron, or the crontab creators primary group.


Overview

Finding ID Version Rule ID IA Controls Severity
V-22385 GEN003050 SV-38358r1_rule ECLP-1 Medium
Description
To protect the integrity of scheduled system jobs and prevent malicious modification to these jobs, crontab files must be secured.
STIG Date
HP-UX 11.23 Security Technical Implementation Guide 2015-12-02

Details

Check Text ( C-36449r3_chk )
Check the group ownership of the crontab files.
# ls -lL /var/spool/cron/crontabs

If the group-owner is not root sys (default), cron, or the crontab owner's primary group, this is a finding.
Fix Text (F-31788r1_fix)
Change the group owner of the crontab file.
# chgrp root