UCF STIG Viewer Logo

The file integrity tool must be configured to verify extended attributes.


Overview

Finding ID Version Rule ID IA Controls Severity
V-22508 GEN006571 M6 SV-38141r1_rule ECAT-1 Low
Description
Extended attributes in file systems are used to contain arbitrary data and file metadata potentially having security implications.
STIG Date
MAC OSX 10.6 Workstation Security Technical Implementation Guide Draft 2013-01-10

Details

Check Text ( C-37510r1_chk )
Open a terminal session and enter the following command to verify the permissions are set to the original installation settings.

diskutil verifyPermissions /

If files are shown with incorrect extended attributes, this is a finding.
Fix Text (F-32913r1_fix)
Open a terminal session and enter the following command to remove extended attributes.

diskutil repairPermissions /